First published: Fri Dec 27 2019(Updated: )
In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrative privileges of the user, allowing an arbitrary file write via a symbolic link attack with file restoration functionality.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
K7 Ultimate Security | =16.0.0117 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-16896 is classified as high due to the potential for arbitrary file write via a symbolic link attack.
To fix CVE-2019-16896, ensure that you upgrade to a newer version of K7 Ultimate Security that patches this vulnerability.
CVE-2019-16896 affects K7 Ultimate Security version 16.0.0117.
CVE-2019-16896 is associated with a symbolic link attack that can lead to arbitrary file write.
The vulnerable component in CVE-2019-16896 is the K7BKCExt.dll module, specifically the backup functionality.