Desktop Software
Memory Corruption
OOB Write Heap Buffer dwCompressionSize MS-WIM
Quick Heal Internet Security Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability We found that the Quick Heal Internet Security is vulnerable to Out of Bound Write…
.png)
Overview
Quick Heal Internet Security Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
We found that the Quick Heal Internet Security is vulnerable to Out of Bound Write on Heap Buffer due to improper validation of dwCompressionSize of Microsoft WIM Header WIMHEADER_V1_PACKED.
This vulnerability can be exploited to gain Remote Code Execution as well as Privilege Escalation.
Vulnerability details
Quick Heal Internet Security Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability We found that the Quick Heal Internet Security is vulnerable to Out of Bound Write on Heap Buffer due to improper validation of
Disclosure timeline
2016-07-13 Reported to vendor
2016-07-15 Received acknowledgement from vendor
2016-07-20 Patch released
References
2026-06-17 (NVD record)
Credits
Ashfaq Ansari – Project Srishti – Payatu Technologies
















