In K7 Antivirus Premium before 15.1.0.53, user-controlled input to the K7Sentry device is not sufficiently authenticated: a local user with a LOW integrity process can access a raw hard disk by sending a specific IOCTL.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/REVRTools/CVEs