First published: Tue Jul 21 2020(Updated: )
In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking to bypass the hips could execute arbitrary code on the Local system.
Credit: security@360.cn
Affected Software | Affected Version | How to fix |
---|---|---|
VirusTotal | <=12.1.0.1004 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15723 is classified as a local privilege escalation vulnerability.
To remediate CVE-2020-15723, upgrade to a version of 360 Total Security later than 12.1.0.1004.
CVE-2020-15723 affects 360 Total Security versions up to and including 12.1.0.1004.
CVE-2020-15723 is a local privilege escalation vulnerability due to DLL hijacking.
While CVE-2020-15723 primarily allows local code execution, exploitation may lead to broader system compromises.