CVE-2019-16897: k7computing k7 Antivirus Premium

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

In K7 Antivirus Premium 16.0.xxx through 16.0.0120; K7 Total Security 16.0.xxx through 16.0.0120; and K7 Ultimate Security 16.0.xxx through 16.0.0120, the module K7TSHlpr.dll improperly validates the administrative privileges of the user, allowing arbitrary registry writes in the K7AVOptn.dll module to facilitate escalation of privileges via inter-process communication with a service process.

Affected products

  • k7computing k7 Antivirus Premium: from 16.0.000, up to and including 16.0.0120
  • k7computing k7 Total Security: from 16.0.000, up to and including 16.0.0120
  • k7computing k7 Ultimate Security: from 16.0.000, up to and including 16.0.0120

Published 2019-10-28. Last modified 2026-06-17.