CVE-2017-17429

In K7 Antivirus Premium before 15.1.0.53, user-controlled input to the K7Sentry device is not sufficiently authenticated: a local user with a LOW integrity process can access a raw hard disk by sending a specific IOCTL.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:k7computing:antivirus:*:*:*:*:premium:*:*:*
cpe:2.3:a:k7computing:antivirus:*:*:*:*:plus:*:*:*
cpe:2.3:a:k7computing:endpoint:*:*:*:*:*:*:*:*
cpe:2.3:a:k7computing:internet_security:*:*:*:*:*:*:*:*
cpe:2.3:a:k7computing:total_security:*:*:*:*:*:*:*:*
cpe:2.3:a:k7computing:total_security:*:*:*:*:plus:*:*:*
cpe:2.3:a:k7computing:ultimate_security:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:17

Type Values Removed Values Added
References () https://support.k7computing.com/index.php?/selfhelp/view-article/Advisory-issued-on-5th-December-2017 - Vendor Advisory () https://support.k7computing.com/index.php?/selfhelp/view-article/Advisory-issued-on-5th-December-2017 - Vendor Advisory

Information

Published : 2018-01-16 19:29

Updated : 2024-11-21 03:17


NVD link : CVE-2017-17429

Mitre link : CVE-2017-17429

CVE.ORG link : CVE-2017-17429


JSON object : View

Products Affected

k7computing

  • ultimate_security
  • total_security
  • internet_security
  • antivirus
  • endpoint
CWE
CWE-20

Improper Input Validation