Lucene search

K
cve[email protected]CVE-2014-9643
HistoryFeb 06, 2015 - 3:59 p.m.

CVE-2014-9643

2015-02-0615:59:11
CWE-264
web.nvd.nist.gov
25
security
k7 computing
vulnerability
cve-2014-9643
memory
privileges
nvd
antivirus

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

26.2%

K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580, 0x950025a8, 0x950025ac, or 0x950025c8 IOCTL call.

Affected configurations

NVD
Node
k7computingk7sentry.sysRange12.8.0.117
AND
k7computinganti-virus_plusRange14.2.0.252
OR
k7computingtotal_securityRange14.2.0.252
OR
k7computingultimate_securityRange14.2.0.252

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

26.2%