A security vulnerability, designated as CVE-2024-36424, has been found in K7 Ultimate Security antivirus software, allowing low-privileged users to escalate their permissions to the SYSTEM level, thus gaining full control over affected Windows devices. The flaw arises from inadequate access controls in the named pipe K7TSMngrService1, which allows limited permission programs to communicate with higher-privileged programs. Attackers can exploit this vulnerability to disable antivirus protection or execute malicious code with SYSTEM privileges. K7 Computing has released several patches to address the issue, but researchers have found ways to bypass these protections. The vulnerability affects K7 Ultimate Security version 17.0.2045 and potentially earlier versions, prompting organizations to upgrade to the latest patched version.