PT-2024-19156 · Qihoo 360 · 360 Total Security Antivirus

Mansk1Es

·

Published

2024-04-15

·

Updated

2025-06-30

·

CVE-2024-22014

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 360 Total Security Antivirus versions 11.0.0.1061 and earlier
Description An issue in 360 Total Security Antivirus allows attackers to gain escalated privileges via Symbolic Link Follow to Arbitrary File Delete. This enables attackers to potentially delete arbitrary files, leading to privilege escalation.
Recommendations For versions 11.0.0.1061 and earlier, update to a version later than 11.0.0.1061 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-22014

Affected Products

360 Total Security Antivirus