📦

total_security

Vendor: k7computing

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 10 Remote Access
Total CVEs 47 Total Indexed
Avg. EPSS 0.51% Exploit Prob.
Latest CVE CVE-2018-9333 Jan 11

Security Vulnerability Index

Page 3 / 5
7.0 CVSS

K7 Antivirus Premium before 15.1.0.53 allows local users to gain privileges by sending a specific IOCTL after setting the memory in a particular way.

EPSS: 0.27%
7.8 CVSS

K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls.

EPSS: 0.33%
7.8 CVSS

K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls.

EPSS: 0.33%
7.1 CVSS
CVE-2017-18019
Exploit Found

In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficiently sanitized: the user-controlled input can be used to compare an arbitrary memory address with a fixed value, which in turn can be used to read the contents of arbitrary memory. Similarly, the product crashes upon a \\.\K7Sentry DeviceIoControl call with an invalid kernel pointer.

EPSS: 1.24%
7.2 CVSS
CVE-2014-9643
Exploit Found

K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580, 0x950025a8, 0x950025ac, or 0x950025c8 IOCTL call.

EPSS: 1.05%