← Vulnerability feed

Vulnerability record · CVE-2017-17429 · published 16 January 2018

CVE-2017-17429: K7computing antivirus improper input validation vulnerability

K7computing · Antivirus

In K7 Antivirus Premium before 15.1.0.53, user-controlled input to the K7Sentry device is not sufficiently authenticated: a local user with a LOW integrity process can access a raw hard disk by sending a specific IOCTL.

5.5 CVSS 3.0 Medium EPSS 0.29% · top 80.6% CWE-20 · Improper input validation
5.5CVSS 3.0 base score, v2 2.1
0.29%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In K7 Antivirus Premium before 15.1.0.53, user-controlled input to the K7Sentry device is not sufficiently authenticated: a local user with a LOW integrity process can access a raw hard disk by sending a specific IOCTL.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-17429 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-17699K7computing antivirus null pointer dereference vulnerabilityK7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025ac DeviceIoControl request.EPSS 1.3%9.8CVE-2017-17700K7computing antivirus null pointer dereference vulnerabilityK7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025a4 DeviceIoControl request.EPSS 1.3%9.8CVE-2017-17701K7computing antivirus null pointer dereference vulnerabilityK7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025c8 DeviceIoControl request.EPSS 1.3%9.8CVE-2017-17464K7computing antivirus null pointer dereference vulnerabilityK7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x95002570 DeviceIoControl request.EPSS 1.3%9.8CVE-2017-17465K7computing antivirus null pointer dereference vulnerabilityK7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x95002574 DeviceIoControl request.EPSS 1.3%9.3CVE-2008-5533K7computing antivirus improper input validation vulnerabilityK7AntiVirus 7.10.541 and possibly 7.10.454, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML …EPSS 3.0%7.8CVE-2018-8044K7computing antivrius improper privilege management vulnerabilityK7Computing Pvt Ltd K7Antivirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: Local Process Execution (local). The compo…EPSS 0.31%7.8CVE-2018-8724K7computing antivrius improper privilege management vulnerabilityK7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: gain privileges (local). The component is:…EPSS 0.27%

Source: NIST National Vulnerability Database (record CVE-2017-17429), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.