First published: Mon May 23 2022(Updated: )
A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, leading to execution of arbitrary code, via the installer not restricting the search path for required DLLs and then not verifying the signature of the DLLs it tries to load.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quickheal Total Security | <12.1.1.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31467 is considered a high-severity vulnerability due to its potential for privilege escalation and arbitrary code execution.
To fix CVE-2022-31467, update Quick Heal Total Security to version 12.1.1.27 or later.
CVE-2022-31467 is a DLL hijacking vulnerability that allows local attackers to exploit the system.
CVE-2022-31467 affects users of Quick Heal Total Security prior to version 12.1.1.27.
Attackers can achieve privilege escalation leading to the execution of arbitrary code on the affected systems.