← Vulnerability feed

Vulnerability record · CVE-2018-5220 · published 4 January 2018

CVE-2018-5220: K7computing antivirus improper input validation vulnerability

K7computing · Antivirus

In K7 Antivirus 15.1.0306, the driver file (K7Sentry.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x95002610.

7.8 CVSS 3.0 High EPSS 0.40% · top 68.5% CWE-20 · Improper input validation
7.8CVSS 3.0 base score, v2 6.1
0.40%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In K7 Antivirus 15.1.0306, the driver file (K7Sentry.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x95002610.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-5220 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-17699K7computing antivirus null pointer dereference vulnerabilityK7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025ac DeviceIoControl request.EPSS 1.3%9.8CVE-2017-17700K7computing antivirus null pointer dereference vulnerabilityK7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025a4 DeviceIoControl request.EPSS 1.3%9.8CVE-2017-17701K7computing antivirus null pointer dereference vulnerabilityK7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025c8 DeviceIoControl request.EPSS 1.3%9.8CVE-2017-17464K7computing antivirus null pointer dereference vulnerabilityK7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x95002570 DeviceIoControl request.EPSS 1.3%9.8CVE-2017-17465K7computing antivirus null pointer dereference vulnerabilityK7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x95002574 DeviceIoControl request.EPSS 1.3%9.3CVE-2008-5533K7computing antivirus improper input validation vulnerabilityK7AntiVirus 7.10.541 and possibly 7.10.454, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML …EPSS 3.0%7.8CVE-2017-16549K7computing antivirus out-of-bounds write vulnerabilityK7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set…EPSS 0.33%7.8CVE-2017-16550K7computing antivirus vulnerabilityK7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set…EPSS 0.33%

Source: NIST National Vulnerability Database (record CVE-2018-5220), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.