HIGH · 7.2

CVE-2014-9643

K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a...

Vulnerability Description

K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580, 0x950025a8, 0x950025ac, or 0x950025c8 IOCTL call.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
K7ComputingK7Sentry.Sys<= 12.8.0.117
K7ComputingAnti-Virus Plus<= 14.2.0.252
K7ComputingTotal Security<= 14.2.0.252
K7ComputingUltimate Security<= 14.2.0.252

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-9643?

CVE-2014-9643 is a vulnerability with a CVSS score of 7.2 (HIGH). K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a...

How severe is CVE-2014-9643?

CVE-2014-9643 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-9643?

Check the references section above for vendor advisories and patch information. Affected products include: K7Computing K7Sentry.Sys, K7Computing Anti-Virus Plus, K7Computing Total Security, K7Computing Ultimate Security.