First published: Tue Jan 16 2018(Updated: )
K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
K7 Computing AntiVirus | <15.1.0.53 | |
K7 Computing AntiVirus | <15.1.0308 | |
k7computing endpoint | <14.2.0137 | |
K7 Computing Internet Security | <15.1.0297 | |
K7 Computing Total Security | <15.1.0324 | |
K7 Computing Total Security | <16.0.0131 | |
K7 Ultimate Security | <15.1.0324 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16550 has a medium severity rating due to its potential to allow local users to gain elevated privileges.
To fix CVE-2017-16550, update K7 Antivirus Premium to version 15.1.0.53 or later.
K7 Antivirus Premium, K7 Total Security, K7 Internet Security, K7 Endpoint Security, and K7 Ultimate Security versions prior to specified updates are affected by CVE-2017-16550.
CVE-2017-16550 facilitates a local privilege escalation attack through specific IOCTL calls.
CVE-2017-16550 is not exploitable remotely as it requires local access to the affected system.