CVE-2019-16896

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
27/12/2019
Last modified:
09/01/2020

Description

In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrative privileges of the user, allowing an arbitrary file write via a symbolic link attack with file restoration functionality.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:k7computing:k7_ultimate_security:16.0.0117:*:*:*:*:*:*:*