CVE-2017-17429: Input Validation
In K7 Antivirus Premium before 15.1.0.53, user-controlled input to the K7Sentry device is not sufficiently authenticated: a local user with a LOW integrity process can access a raw hard disk by sending a specific IOCTL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-17429?
CVE-2017-17429 has a high severity level due to its potential to allow local users to access raw hard disk data without proper authentication.
How do I fix CVE-2017-17429?
To fix CVE-2017-17429, users should update K7 Antivirus Premium to version 15.1.0.53 or later.
What software versions are affected by CVE-2017-17429?
CVE-2017-17429 affects K7 Antivirus Premium versions prior to 15.1.0.53 and other K7 products with similar version limitations.
Is CVE-2017-17429 a local or remote vulnerability?
CVE-2017-17429 is a local vulnerability that requires physical access to the affected machine.
What kind of attack can exploit CVE-2017-17429?
An attacker can exploit CVE-2017-17429 by sending a specific IOCTL to gain unauthorized access to raw hard disk data.