CVE-2025-1055

Media5.6Publicada el 11 de junio de 2025

A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to terminate a wide range of processes running with administrative or system-level privileges, with the exception of those inherently protected by the operating system. This flaw stems from missing access control in the driver's IOCTL handler, enabling unprivileged users to perform privileged actions in kernel space. Successful exploitation can lead to denial of service by disrupting critical services or privileged applications.

Preaviso: explotación observada

  • Explotación observada desde el 16 jun 2026
  • Todavía no está en el catálogo oficial de CISA
  • Primer ataque observado 370 días después de la divulgación
  • Utilizada en campañas de ransomware

Fuente: VulnCheck KEV · 1 oct 2026 16 jun 2026

Puntuación CVSS5.6 / 10CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
Tipo de debilidad (CWE)CWE-862

Artículos relacionados

This product uses the NVD API but is not endorsed or certified by the NVD.

Base de datos CVE