CVE-2014-9643 is a local privilege escalation vulnerability affecting K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security products prior to version 14.2.0.253. It allows a local attacker to write to arbitrary memory locations by crafting specific IOCTL calls to the K7Sentry.sys driver. Rated with a CVSS score of 7.2, this vulnerability has a high impact on confidentiality, integrity, and availability, requiring local access with low attack complexity. The FAUCET Risk Score is 86/100, indicating significant risk. While not listed in CISA's KEV catalog, an exploit for this vulnerability is publicly available on ExploitDB. There is no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 12.8.0.117CPE matchmatch criteria | cpe:2.3:a:k7computing:k7sentry.sys:*:*:*:*:*:*:*:* | ||
<= 14.2.0.252CPE matchmatch criteria | cpe:2.3:a:k7computing:anti-virus_plus:*:*:*:*:*:*:*:* | ||
<= 14.2.0.252CPE matchmatch criteria | cpe:2.3:a:k7computing:total_security:*:*:*:*:*:*:*:* | ||
<= 14.2.0.252CPE matchmatch criteria | cpe:2.3:a:k7computing:ultimate_security:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.