CVE-2025-1055
K7 Security Anti-Malware: IOCTL in K7RKScan.sys Allows Arbitrary Termination of High-Privilege and System Processes by a Low-Privilege User
Description
A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to terminate a wide range of processes running with administrative or system-level privileges, with the exception of those inherently protected by the operating system. This flaw stems from missing access control in the driver's IOCTL handler, enabling unprivileged users to perform privileged actions in kernel space. Successful exploitation can lead to denial of service by disrupting critical services or privileged applications.
CVSS Vector Breakdown
AV:LAttack VectorAC:HAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:CScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- DragonForce Hides Backdoor C2 Inside Microsoft Teams TURN Relaysen-us·Daily CyberSecurity (securityonline.info)· Exploited Microsoft Teams Hackledorb
- DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Trafficen·The Hacker News· Exploited Backdoor.Turn DragonForce
- Ransomware gang abuses Microsoft Teams relays to hide malicious trafficen-us·BleepingComputer· Exploited Microsoft Teams DragonForce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-1055 and every CVE in our database. Create a free account — no credit card required.
Create Free Account