CVE-2020-9362: High severity QuickHeal Antivirus For Server vulnerability
The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. This affects Total Security, Home Security, Total Security Multi-Device, Internet Security, Total Security for Mac, AntiVirus Pro, AntiVirus for Server, and Total Security for Android.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9362?
The severity of CVE-2020-9362 is classified as medium, indicating a moderate risk of exploitation.
How do I fix CVE-2020-9362?
To fix CVE-2020-9362, users should update to the latest version of Quick Heal antivirus software that addresses this vulnerability.
What software is affected by CVE-2020-9362?
CVE-2020-9362 affects various Quick Heal products, including Total Security, Home Security, and Antivirus Pro, all from the November 2019 version.
Can CVE-2020-9362 be exploited remotely?
CVE-2020-9362 can potentially be exploited locally by an attacker who has access to upload crafted ZIP files.
What are the implications of CVE-2020-9362?
The implications of CVE-2020-9362 include possible virus-detection bypass that can allow malware within crafted ZIP archives to evade detection.