CVE-2025-67826: k7computing k7 Ultimate Security
High severity, CVSS 7.7. EPSS: 0.1% chance of exploitation in the next 30 days.
An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ultimate Security antivirus can be exploited by a local unprivileged user on default installations of the product. Insecure access to a named pipe allows unprivileged users to edit any registry key, leading to a full compromise as SYSTEM.
Affected products
- k7computing k7 Ultimate Security: version 17.0.2045 only
Published 2025-12-22. Last modified 2026-06-17.