PT-2018-18425 · Quick Heal · Quick Heal Internet Security+2
Kernelm0De
·
Published
2018-07-25
·
Updated
2021-09-13
·
CVE-2018-8090
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Quick Heal Total Security 64 bit 17.00 versions 10.0.1.38
Quick Heal Total Security 32 bit 17.00 versions 10.0.1.38
Quick Heal Internet Security 64 bit 17.00 versions 10.0.0.37
Quick Heal Internet Security 32 bit 17.00 versions 10.0.0.37
Quick Heal AntiVirus Pro 64 bit 17.00 versions 10.0.0.37
Quick Heal AntiVirus Pro 32 bit 17.00 versions 10.0.0.37
Description:
The issue is related to DLL Hijacking due to Insecure Library Loading. This allows for potential exploitation.
Recommendations:
For Quick Heal Total Security 64 bit 17.00 version 10.0.1.38, update to a version that addresses the Insecure Library Loading issue.
For Quick Heal Total Security 32 bit 17.00 version 10.0.1.38, update to a version that addresses the Insecure Library Loading issue.
For Quick Heal Internet Security 64 bit 17.00 version 10.0.0.37, update to a version that addresses the Insecure Library Loading issue.
For Quick Heal Internet Security 32 bit 17.00 version 10.0.0.37, update to a version that addresses the Insecure Library Loading issue.
For Quick Heal AntiVirus Pro 64 bit 17.00 version 10.0.0.37, update to a version that addresses the Insecure Library Loading issue.
For Quick Heal AntiVirus Pro 32 bit 17.00 version 10.0.0.37, update to a version that addresses the Insecure Library Loading issue.
As a temporary workaround, consider restricting the loading of libraries to minimize the risk of exploitation.
Exploit
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quick Heal Antivirus Pro
Quick Heal Internet Security
Quick Heal Total Security