CVE-2018-5217: Input Validation
Published Jan 4, 2018
·Updated
In K7 Antivirus 15.1.0306, the driver file (K7Sentry.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x95002578.
Affected Software
1 affected component
K7Computing Antivirus=15.1.0306
Event History
Jan 4, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-5217?
CVE-2018-5217 has a medium severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2018-5217?
To fix CVE-2018-5217, update K7 Antivirus to a version that addresses this vulnerability.
3
Who is affected by CVE-2018-5217?
CVE-2018-5217 affects users of K7 Antivirus version 15.1.0306.
4
What impact can CVE-2018-5217 have?
CVE-2018-5217 can lead to a denial of service resulting in a blue screen of death (BSOD) for local users.
5
What is the cause of CVE-2018-5217?
CVE-2018-5217 is caused by the K7Sentry.sys driver not validating input values from specific IOCTL calls.