First published: Tue Jul 21 2020(Updated: )
In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking to bypass the hips could execute arbitrary code on the Local system.
Credit: security@360.cn
Affected Software | Affected Version | How to fix |
---|---|---|
G DATA Total Security | <=12.1.0.1005 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15724 is classified as a local privilege escalation vulnerability that can lead to arbitrary code execution.
To mitigate CVE-2020-15724, users should upgrade to versions of 360 Total Security above 12.1.0.1005.
CVE-2020-15724 is caused by a DLL hijacking vulnerability in 360 Total Security when GameChrome.exe is called from the Gamefolder.
CVE-2020-15724 affects users running version 12.1.0.1005 or below of 360 Total Security.
CVE-2020-15724 requires local access, as the vulnerability must be exploited on the affected system.