Desktop Software

Remote Code Execution

Insecure Library Loading

Quick Heal Internet Security Uncontrolled Search Path Element Vulnerability We found that the Quick Heal Installer Downloader (QuickHealInternetSecurity.EXE) and Quick Heal Installer (QHISFT32.EXE)…

7.5
/ 10
High
CVSS v3.1
ADVISORY ID
PS8
PUBLISHED
2022-10-02
CVE IDs
CVE-2017-8776
VENDORS
Quick Heal
PUBLIC EXPLOIT
None indexed
CWE
PRODUCT
Quick Heal Internet Security / Total Security / AntiVirus Pro
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Quick Heal Internet Security Uncontrolled Search Path Element Vulnerability

We found that the Quick Heal Installer Downloader (QuickHealInternetSecurity.EXE) and Quick Heal Installer (QHISFT32.EXE) application uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actor.

This vulnerability is called as Insecure Library Loading also known as DLL Hijacking attack.

Vulnerability details

Vulnerability details

CVE-2017-8776
High | 7.5

Quick Heal Internet Security Uncontrolled Search Path Element Vulnerability We found that the Quick Heal Installer Downloader (QuickHealInternetSecurity.EXE) and Quick Heal Installer (QHISFT32.EXE) application uses a fixed or controlled search path to find

Impact:
Arbitrary data or code modification
DISCLOSURE

Disclosure timeline

2016-06-09 Reported to vendor

2016-06-11 Received acknowledgement from vendor

2016-08-01 Patch released

References

Credits

Ashfaq Ansari – Project Srishti – Payatu Technologies