CVE-2017-18019: Input Validation
In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficiently sanitized: the user-controlled input can be used to compare an arbitrary memory address with a fixed value, which in turn can be used to read the contents of arbitrary memory. Similarly, the product crashes upon a \\.\K7Sentry DeviceIoControl call with an invalid kernel pointer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18019?
CVE-2017-18019 has a medium severity rating due to its potential for unauthorized memory access.
How do I fix CVE-2017-18019?
To fix CVE-2017-18019, update K7 Total Security to version 15.1.0.305 or later.
What software is affected by CVE-2017-18019?
CVE-2017-18019 affects K7 Total Security versions prior to 15.1.0.305.
What type of vulnerability is CVE-2017-18019?
CVE-2017-18019 is a memory access vulnerability caused by insufficient input sanitization.
Can CVE-2017-18019 lead to data breaches?
Yes, CVE-2017-18019 could potentially allow attackers to read sensitive information from memory.