CVE-2014-9643: k7computing Anti-Virus Plus

High severity, CVSS 7.2. EPSS: 1% chance of exploitation in the next 30 days.

K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580, 0x950025a8, 0x950025ac, or 0x950025c8 IOCTL call.

Affected products

  • k7computing Anti-Virus Plus: up to and including 14.2.0.252
  • k7computing k7sentry.sys: up to and including 12.8.0.117
  • k7computing Total Security: up to and including 14.2.0.252
  • k7computing Ultimate Security: up to and including 14.2.0.252

Published 2015-02-06. Last modified 2026-06-17.