CVE-2025-63685

Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of system libraries. Specifically, the application does not validate the path or signature of [regsvr32.exe] it loads. An attacker can place a crafted malicious DLL in the application's startup directory, which will be loaded and executed when the user launches the program.
References
Link Resource
https://github.com/QIU-DIE/CVE/issues/5 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:quark:quark_cloud_drive:3.23.2:*:*:*:*:*:*:*

History

16 Dec 2025, 18:05

Type Values Removed Values Added
First Time Quark quark Cloud Drive
Quark
CPE cpe:2.3:a:quark:quark_cloud_drive:3.23.2:*:*:*:*:*:*:*
References () https://github.com/QIU-DIE/CVE/issues/5 - () https://github.com/QIU-DIE/CVE/issues/5 - Exploit, Issue Tracking, Third Party Advisory

21 Nov 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 9.8

20 Nov 2025, 22:16

Type Values Removed Values Added
CWE CWE-491
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

20 Nov 2025, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-20 21:16

Updated : 2025-12-16 18:05


NVD link : CVE-2025-63685

Mitre link : CVE-2025-63685

CVE.ORG link : CVE-2025-63685


JSON object : View

Products Affected

quark

  • quark_cloud_drive
CWE
CWE-491

Public cloneable() Method Without Final ('Object Hijack')