Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-63685

Опубликовано: 20 нояб. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of system libraries. Specifically, the application does not validate the path or signature of [regsvr32.exe] it loads. An attacker can place a crafted malicious DLL in the application's startup directory, which will be loaded and executed when the user launches the program.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:quark:quark_cloud_drive:3.23.2:*:*:*:*:*:*:*

EPSS

Процентиль: 23%
0.00076
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-491

Связанные уязвимости

CVSS3: 7.5
github
3 месяца назад

Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of system libraries. Specifically, the application does not validate the path or signature of [regsvr32.exe] it loads. An attacker can place a crafted malicious DLL in the application's startup directory, which will be loaded and executed when the user launches the program.

EPSS

Процентиль: 23%
0.00076
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-491