Desktop Software
Remote Code Execution
Insecure Library Loading
Quick Heal Internet Security Uncontrolled Search Path Element Vulnerability We found that the Quick Heal Installer Downloader (QuickHealInternetSecurity.EXE) and Quick Heal Installer (QHISFT32.EXE)…
.png)
Overview
Quick Heal Internet Security Uncontrolled Search Path Element Vulnerability
We found that the Quick Heal Installer Downloader (QuickHealInternetSecurity.EXE) and Quick Heal Installer (QHISFT32.EXE) application uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actor.
This vulnerability is called as Insecure Library Loading also known as DLL Hijacking attack.
Vulnerability details
Quick Heal Internet Security Uncontrolled Search Path Element Vulnerability We found that the Quick Heal Installer Downloader (QuickHealInternetSecurity.EXE) and Quick Heal Installer (QHISFT32.EXE) application uses a fixed or controlled search path to find
Disclosure timeline
2016-06-09 Reported to vendor
2016-06-11 Received acknowledgement from vendor
2016-08-01 Patch released
References
2026-06-17 (NVD record)
Credits
Ashfaq Ansari – Project Srishti – Payatu Technologies
















