Описание
In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrative privileges of the user, allowing an arbitrary file write via a symbolic link attack with file restoration functionality.
Ссылки
- ExploitThird Party Advisory
- Vendor Advisory
- ExploitThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:k7computing:k7_ultimate_security:16.0.0117:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00221
Низкий
7.8 High
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-59
Связанные уязвимости
github
больше 3 лет назад
In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrative privileges of the user, allowing an arbitrary file write via a symbolic link attack with file restoration functionality.
EPSS
Процентиль: 45%
0.00221
Низкий
7.8 High
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-59