Quickheal
Quickheal Total Security: vulnerabilities and CVEs
Quickheal Total Security has 15 published vulnerabilities, 1 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.
CVEs15
Last 12 months1
Critical4
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69875 | High (7.8) | 0.12% | — | Feb 3, 2026 | A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to… |
| CVE-2024-48292 | High (8.8) | 0.38% | — | Nov 18, 2024 | An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackers to escalate privileges. |
| CVE-2022-31467 | High (7.3) | 0.29% | — | May 23, 2022 | A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, leading to execution of arbitrary code, via the installer not… |
| CVE-2022-31466 | High (7) | 0.16% | — | May 23, 2022 | Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, potentially leading to deletion of system files. This is… |
| CVE-2020-27587 | Medium (6.7) | 0.36% | — | Nov 30, 2020 | Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vault via a brute-force attack on the password. |
| CVE-2020-27586 | Medium (5.9) | 0.70% | — | Nov 30, 2020 | Quick Heal Total Security before version 19.0 transmits quarantine and sysinfo files via clear text. |
| CVE-2020-27585 | Medium (4.4) | 0.32% | — | Nov 30, 2020 | Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings via a brute-attack on the settings password. |
| CVE-2020-9362 | High (7.8) | 1.5% | — | Feb 24, 2020 | The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. This affects Total Security, Home Security, Total Security Multi-Device, Internet Security, Total… |
| CVE-2018-8090 | High (7.8) | 1.2% | — | Jul 25, 2018 | Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00 (QHTS32.exe), (QHTSFT32.exe) - Version 10.0.1.38; Quick Heal Internet Security 64 bit 17.00… |
| CVE-2017-8776 | High (7.5) | 0.93% | — | May 4, 2017 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 have approximately 165 PE files in the default installation that do not use ASLR/DEP protection… |
| CVE-2017-8775 | Critical (9.8) | 1.2% | — | May 4, 2017 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memory Corruption while parsing a malformed Mach-O file. |
| CVE-2017-8774 | Critical (9.8) | 1.2% | — | May 4, 2017 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memory Corruption while parsing a malformed Mach-O file. |
| CVE-2017-8773 | Critical (9.8) | 2.3% | — | May 4, 2017 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Out of Bounds Write on a Heap Buffer due to improper validation of… |
| CVE-2015-8285 | High (7.5) | 5.5% | — | Apr 20, 2017 | The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service. |
| CVE-2017-5005 | Critical (9.8) | 9.7% | — | Jan 2, 2017 | Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro 10.1.0.316 and earlier on OS X allows remote attackers to execute arbitrary… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.