4.4
CVSSv2

CVE-2022-31466

Published: 23/05/2022 Updated: 08/08/2023
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security before 12.1.1.27 allows a local malicious user to achieve privilege escalation, potentially leading to deletion of system files. This is achieved through exploiting the time between detecting a file as malicious and when the action of quarantining or cleaning is performed, and using the time to replace the malicious file by a symlink.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

quickheal total security