CVE-2014-5307: Pandasecurity Panda AV Pro 2014
High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.
Heap-based buffer overflow in the PavTPK.sys kernel mode driver of Panda Security 2014 products before hft131306s24_r1 allows local users to gain privileges via a crafted argument to a 0x222008 IOCTL call.
Affected products
- Pandasecurity Panda AV Pro 2014: version 13.01.01 only
- Pandasecurity Panda Global Protection 2014: version 7.01.01 only
- Pandasecurity Panda Internet Security 2014: version 19.01.01 only
Published 2014-08-26. Last modified 2026-06-17.