PT-2018-18425 · Quick Heal · Quick Heal Internet Security+2

Kernelm0De

·

Published

2018-07-25

·

Updated

2021-09-13

·

CVE-2018-8090

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Quick Heal Total Security 64 bit 17.00 versions 10.0.1.38 Quick Heal Total Security 32 bit 17.00 versions 10.0.1.38 Quick Heal Internet Security 64 bit 17.00 versions 10.0.0.37 Quick Heal Internet Security 32 bit 17.00 versions 10.0.0.37 Quick Heal AntiVirus Pro 64 bit 17.00 versions 10.0.0.37 Quick Heal AntiVirus Pro 32 bit 17.00 versions 10.0.0.37
Description: The issue is related to DLL Hijacking due to Insecure Library Loading. This allows for potential exploitation.
Recommendations: For Quick Heal Total Security 64 bit 17.00 version 10.0.1.38, update to a version that addresses the Insecure Library Loading issue. For Quick Heal Total Security 32 bit 17.00 version 10.0.1.38, update to a version that addresses the Insecure Library Loading issue. For Quick Heal Internet Security 64 bit 17.00 version 10.0.0.37, update to a version that addresses the Insecure Library Loading issue. For Quick Heal Internet Security 32 bit 17.00 version 10.0.0.37, update to a version that addresses the Insecure Library Loading issue. For Quick Heal AntiVirus Pro 64 bit 17.00 version 10.0.0.37, update to a version that addresses the Insecure Library Loading issue. For Quick Heal AntiVirus Pro 32 bit 17.00 version 10.0.0.37, update to a version that addresses the Insecure Library Loading issue. As a temporary workaround, consider restricting the loading of libraries to minimize the risk of exploitation.

Exploit

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-8090

Affected Products

Quick Heal Antivirus Pro
Quick Heal Internet Security
Quick Heal Total Security