CVE-2017-8776: High severity quickheal antivirus plus 2009 vulnerability
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 have approximately 165 PE files in the default installation that do not use ASLR/DEP protection mechanisms that provide sufficient defense against directed attacks against the product.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8776?
CVE-2017-8776 is considered a high severity vulnerability due to its exploitation potential affecting multiple Quick Heal products.
How do I fix CVE-2017-8776?
To address CVE-2017-8776, update to the latest versions of Quick Heal products that remediate the issue.
Which Quick Heal products are affected by CVE-2017-8776?
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are affected by CVE-2017-8776.
What protections are lacking in CVE-2017-8776?
CVE-2017-8776 lacks Address Space Layout Randomization (ASLR) and Data Execution Prevention (DEP) protection mechanisms.
How can CVE-2017-8776 be exploited?
CVE-2017-8776 can be exploited through directed attacks that target the vulnerable PE files in the affected Quick Heal software.