First published: Fri Dec 27 2019(Updated: )
In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrative privileges of the user, allowing an arbitrary file write via a symbolic link attack with file restoration functionality.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
K7computing K7 Ultimate Security | =16.0.0117 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.