First published: Thu May 04 2017(Updated: )
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Out of Bounds Write on a Heap Buffer due to improper validation of dwCompressionSize of Microsoft WIM Header WIMHEADER_V1_PACKED. This vulnerability can be exploited to gain Remote Code Execution as well as Privilege Escalation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
QuickHeal Antivirus Pro | <=10.1.0.316 | |
Quickheal Internet Security | <=10.1.0.316 | |
Quickheal Total Security | <=10.1.0.316 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8773 is considered a high severity vulnerability due to its potential impact on system stability and data integrity.
To mitigate CVE-2017-8773, users should update to the latest versions of Quick Heal Internet Security, Total Security, or AntiVirus Pro that address this vulnerability.
CVE-2017-8773 affects Quick Heal Internet Security, Total Security, and AntiVirus Pro versions up to and including 10.1.0.316.
CVE-2017-8773 is classified as an Out of Bounds Write vulnerability on a Heap Buffer, which can lead to exploitation.
Yes, CVE-2017-8773 may allow attackers to execute arbitrary code, making it a significant security concern.