Quickheal
Quickheal Total Security: vulnerabilidades y CVE
Quickheal Total Security tiene 15 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses1
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-69875 | Alta (7.8) | 0.12% | — | 3 feb 2026 | A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to… |
| CVE-2024-48292 | Alta (8.8) | 0.38% | — | 18 nov 2024 | An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackers to escalate privileges. |
| CVE-2022-31467 | Alta (7.3) | 0.29% | — | 23 may 2022 | A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, leading to execution of arbitrary code, via the installer not… |
| CVE-2022-31466 | Alta (7) | 0.16% | — | 23 may 2022 | Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, potentially leading to deletion of system files. This is… |
| CVE-2020-27587 | Media (6.7) | 0.36% | — | 30 nov 2020 | Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vault via a brute-force attack on the password. |
| CVE-2020-27586 | Media (5.9) | 0.70% | — | 30 nov 2020 | Quick Heal Total Security before version 19.0 transmits quarantine and sysinfo files via clear text. |
| CVE-2020-27585 | Media (4.4) | 0.32% | — | 30 nov 2020 | Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings via a brute-attack on the settings password. |
| CVE-2020-9362 | Alta (7.8) | 1.5% | — | 24 feb 2020 | The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. This affects Total Security, Home Security, Total Security Multi-Device, Internet Security, Total… |
| CVE-2018-8090 | Alta (7.8) | 1.2% | — | 25 jul 2018 | Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00 (QHTS32.exe), (QHTSFT32.exe) - Version 10.0.1.38; Quick Heal Internet Security 64 bit 17.00… |
| CVE-2017-8776 | Alta (7.5) | 0.93% | — | 4 may 2017 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 have approximately 165 PE files in the default installation that do not use ASLR/DEP protection… |
| CVE-2017-8775 | Crítica (9.8) | 1.2% | — | 4 may 2017 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memory Corruption while parsing a malformed Mach-O file. |
| CVE-2017-8774 | Crítica (9.8) | 1.2% | — | 4 may 2017 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memory Corruption while parsing a malformed Mach-O file. |
| CVE-2017-8773 | Crítica (9.8) | 2.3% | — | 4 may 2017 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Out of Bounds Write on a Heap Buffer due to improper validation of… |
| CVE-2015-8285 | Alta (7.5) | 5.5% | — | 20 abr 2017 | The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service. |
| CVE-2017-5005 | Crítica (9.8) | 9.7% | — | 2 ene 2017 | Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro 10.1.0.316 and earlier on OS X allows remote attackers to execute arbitrary… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.