First published: Tue Jul 21 2020(Updated: )
In version 12.1.0.1004 and below of 360 Total Security,when TPI calls the browser process, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking could execute arbitrary code on the Local system.
Credit: security@360.cn
Affected Software | Affected Version | How to fix |
---|---|---|
VirusTotal | <=12.1.0.1004 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15722 is classified as a local privilege escalation vulnerability.
To fix CVE-2020-15722, upgrade 360 Total Security to version 12.1.0.1005 or later.
CVE-2020-15722 affects 360 Total Security version 12.1.0.1004 and below.
Yes, CVE-2020-15722 can allow an attacker to execute arbitrary code on the local system.
Yes, CVE-2020-15722 involves a vulnerability that can be exploited through DLL hijacking.