Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4wm7-8hvv-947f

Опубликовано: 20 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of system libraries. Specifically, the application does not validate the path or signature of [regsvr32.exe] it loads. An attacker can place a crafted malicious DLL in the application's startup directory, which will be loaded and executed when the user launches the program.

Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of system libraries. Specifically, the application does not validate the path or signature of [regsvr32.exe] it loads. An attacker can place a crafted malicious DLL in the application's startup directory, which will be loaded and executed when the user launches the program.

EPSS

Процентиль: 23%
0.00076
Низкий

7.5 High

CVSS3

Дефекты

CWE-491

Связанные уязвимости

CVSS3: 9.8
nvd
3 месяца назад

Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of system libraries. Specifically, the application does not validate the path or signature of [regsvr32.exe] it loads. An attacker can place a crafted malicious DLL in the application's startup directory, which will be loaded and executed when the user launches the program.

EPSS

Процентиль: 23%
0.00076
Низкий

7.5 High

CVSS3

Дефекты

CWE-491