CVE-2025-52915: High severity K7 Computing K7 Security Anti-Malware vulnerability
K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a third-party implementation. This is caused by insufficient caller validation in the driver's IOCTL handler, enabling unauthorized processes to perform those actions in kernel space. Successful exploitation can lead to denial of service by disrupting critical third-party services or applications.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52915?
The severity of CVE-2025-52915 is rated as high with a CVSS score of 7.2.
How do I fix CVE-2025-52915?
To fix CVE-2025-52915, update the K7 Security Anti-Malware suite to the latest version provided by K7 Computing.
Who is affected by CVE-2025-52915?
CVE-2025-52915 affects users of K7 Security Anti-Malware versions including K7RKScan.sys 23.0.0.10 who have admin privileges.
What types of attacks could exploit CVE-2025-52915?
CVE-2025-52915 could be exploited by an admin-privileged user to send crafted IOCTL requests that terminate protected processes.
What are the potential impacts of CVE-2025-52915?
The potential impacts of CVE-2025-52915 include unauthorized termination of security processes, leading to a compromised security posture.