CVE-2025-67826: High severity K7 Computing K7 Ultimate Security vulnerability
An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ultimate Security antivirus can be exploited by a local unprivileged user on default installations of the product. Insecure access to a named pipe allows unprivileged users to edit any registry key, leading to a full compromise as SYSTEM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67826?
CVE-2025-67826 is classified as a local privilege escalation vulnerability.
How do I fix CVE-2025-67826?
To mitigate CVE-2025-67826, update K7 Ultimate Security to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-67826?
CVE-2025-67826 affects local unprivileged users on default installations of K7 Ultimate Security.
What types of exploits are possible with CVE-2025-67826?
CVE-2025-67826 can be exploited to gain elevated privileges on the affected system.
Is there a workaround for CVE-2025-67826 until a patch is available?
Currently, the recommended course of action for CVE-2025-67826 is to apply any available updates from K7 Computing.