7.2
CVSSv2

CVE-2014-9643

Published: 06/02/2015 Updated: 09/02/2015
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security prior to 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580, 0x950025a8, 0x950025ac, or 0x950025c8 IOCTL call.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

k7computing k7sentry.sys

k7computing anti-virus_plus

k7computing total_security

k7computing ultimate_security

Exploits

/* Exploit Title - K7 Computing Multiple Products Arbitrary Write Privilege Escalation Date - 04th February 2015 Discovered by - Parvez Anwar (@parvezghh) Vendor Homepage - wwwk7computingcouk/ Tested Version - 1420240 Driver Version - 1280104 - K7Sentrysys Tested on OS - 32bit Windows XP SP3 OSVDB ...
Multiple products from K7 Computing suffer from an arbitrary write privilege escalation vulnerability ...