CVE-2025-67826

Published: Dic 22, 2025 Last Modified: Gen 02, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,7
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: none

Description

AI Translation Available

An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ultimate Security antivirus can be exploited by a local unprivileged user on default installations of the product. Insecure access to a named pipe allows unprivileged users to edit any registry key, leading to a full compromise as SYSTEM.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0002
Percentile
0,0th
Updated

EPSS Score Trend (Last 84 Days)

269

Improper Privilege Management

Draft
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
View CWE Details
Application

K7 Ultimate Security by K7Computing

cpe:2.3:a:k7computing:k7_ultimate_security:17.0.2045:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://support.k7computing.com/index.php?/selfhelp/view-article/Advisory-issue…
https://www.k7computing.com/