CVE-2019-16896: k7computing k7 Ultimate Security
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrative privileges of the user, allowing an arbitrary file write via a symbolic link attack with file restoration functionality.
Affected products
- k7computing k7 Ultimate Security: version 16.0.0117 only
Published 2019-12-27. Last modified 2026-06-17.