CVE-2018-5220: Input Validation
Published Jan 4, 2018
·Updated
In K7 Antivirus 15.1.0306, the driver file (K7Sentry.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x95002610.
Affected Software
1 affected component
K7Computing Antivirus=15.1.0306
Event History
Jan 4, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-5220?
CVE-2018-5220 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2018-5220?
To mitigate CVE-2018-5220, it is recommended to update K7 Antivirus to the latest version that addresses this vulnerability.
3
What types of impacts can CVE-2018-5220 cause?
CVE-2018-5220 can cause a denial of service resulting in a Blue Screen of Death (BSOD) and potentially other unspecified impacts.
4
Which versions of K7 Antivirus are affected by CVE-2018-5220?
CVE-2018-5220 specifically affects K7 Antivirus version 15.1.0306.
5
How does CVE-2018-5220 exploit the K7 Antivirus driver?
CVE-2018-5220 exploits the driver file K7Sentry.sys by not validating input values from IOCtl 0x95002610.