目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-36424 PoC — K7 Computing Ultimate Security 安全漏洞

来源
关联漏洞
标题: K7 Computing Ultimate Security 安全漏洞 (CVE-2024-36424)
Description:K7 Computing Ultimate Security是美国K7 Computing公司的一套适用于Windows平台的防病毒软件。 K7 Computing Ultimate Security 17.0.2019之前版本存在安全漏洞,该漏洞源于 K7RKScan.sys 中存在空指针取消引用漏洞,可能导致拒绝服务。
Description
K7 Ultimate Security < v17.0.2019 "K7RKScan.sys" Null Pointer Dereference PoC 
介绍
# CVE-2024-36424

This vulnerability was discovered and disclosed by **M. Akil Gündoğan** from **Secunnix Vulnerability Research Team**. This repository will hold the proof-of concept and advisories.

# Details:

- **Product:** K7 Ultimate Security
- **Affected versions:** < v17.0.2019
- **CVE ID:** CVE-2024-36424
- **Operating System:** All supported Windows versions, tested on Windows 10 Pro
- **State:** Coordianted responsible disclosure.
- **Release Date:** 13.08.2024

# Vulnerability Description:

In **K7 Ultimate Security < v17.0.2019**, the driver file **(K7RKScan.sys - this version 15.1.0.7)** allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of null pointer dereference from IOCtl **0x222010** and **0x222014**. At the same time, the drive is accessible to all users in the "Everyone" group. 

Technical details and step by step Proof of Concept's (PoC):

    1 - Install the driver in the path "C:\Program Files (x86)\K7 Computing\K7TSecurity\K7TSecurity\64Bit\K7RKScan.sys" to the system via OSRLoader or sc create.
    2 - Compile the attached PoC code written in C++ as release on VS 2022. 
    3 - Run the compiled PoC directly with a double click. You will see the system crash/BSOD.

Tested on: Windows 10 Pro x64, 22H2

![](/screenshot.png)

# Impact:

An attacker with unauthorized user access can cause the entire system to crash and terminate critical processes, including any antivirus process where the relevant driver is activated and used on the system.

# Advisories:

K7 Computing recommends that all customers update their products to the corresponding versions shown below:

K7 Ultimate Security (17.0.2019 or Higher)

# Timeline:

- 16.05.2024 - Vulnerability reported.
- 05.08.2024 - Vendor has fixed the vulnerability.
- 13.08.2024 - Released.

# References:

- Vendor: https://www.k7computing.com
- Advisory: https://support.k7computing.com/index.php?/selfhelp/view-article/Advisory-issued-on-5th-aug-2024-417
- CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36424
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →