vendor:
K7 Ultimate Security
by:
M. Akil Gündoğan
6.1
CVSS
HIGH
Denial of Service (DoS)
119
CWE
Product Name: K7 Ultimate Security
Affected Version From: K7 Ultimate Security < 17.0.2019
Affected Version To: K7 Ultimate Security 17.0.2019
Patch Exists: YES
Related CWE: CVE-2024-36424
CPE: a:k7computing:k7_ultimate_security
Platforms Tested: Windows 10 Pro x64
2024
Denial of Service (DoS) in K7 Ultimate Security K7RKScan.sys
The K7 Ultimate Security version less than 17.0.2019, specifically the driver file K7RKScan.sys version 15.1.0.7, allows local users to perform a Denial of Service (DoS) attack by triggering a null pointer dereference from IOCtl 0x222010 and 0x222014. The driver is accessible to all users in the 'Everyone' group, potentially leading to a system crash (BSOD) or other unspecified impacts.
Mitigation:
Users are advised to update their K7 Ultimate Security to version 17.0.2019 or higher to mitigate this vulnerability.