CVE-2022-31467: DLL Hijacking Vulnerability in Quick Heal Total Security
A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, leading to execution of arbitrary code, via the installer not restricting the search path for required DLLs and then not verifying the signature of the DLLs it tries to load.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-31467?
CVE-2022-31467 is considered a high-severity vulnerability due to its potential for privilege escalation and arbitrary code execution.
How do I fix CVE-2022-31467?
To fix CVE-2022-31467, update Quick Heal Total Security to version 12.1.1.27 or later.
What type of vulnerability is CVE-2022-31467?
CVE-2022-31467 is a DLL hijacking vulnerability that allows local attackers to exploit the system.
Who is affected by CVE-2022-31467?
CVE-2022-31467 affects users of Quick Heal Total Security prior to version 12.1.1.27.
What can attackers achieve with CVE-2022-31467?
Attackers can achieve privilege escalation leading to the execution of arbitrary code on the affected systems.