K7 Total Security Device Driver...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Vulnerability Summary The following advisory describes an Crash found in K7 Total Security. ### Credit An independent security researcher, has reported this vulnerability to Beyond Security’s SecuriTeam Secure Disclosure program ### Vendor response K7 has released patches to address this vulnerability – K7TotalSecurity version 15.1.0.305 ### Vulnerability details User controlled input to K7Sentry device is not sufficiently sanitized, the user controlled input can be used to compare an arbitrary memory address with a fixed value which in turn can be used to read the content of arbitrary memory. ### Crash report By sending invalid kernel pointer we can crash the K7 Total Security process as shown here: ``` 1: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* PAGE_FAULT_IN_NONPAGED_AREA (50) Invalid system memory was...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息