CVE-2025-69875

A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to restore quarantined files into protected system directories. This behavior can be abused by a local attacker to place files in high-privilege locations, potentially leading to privilege escalation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:quickheal:total_security:23.0.0:*:*:*:*:-:*:*

History

11 Feb 2026, 16:06

Type Values Removed Values Added
First Time Quickheal total Security
Quickheal
References () https://github.com/mertdas/QuickHealTotalSecurityPOC - () https://github.com/mertdas/QuickHealTotalSecurityPOC - Third Party Advisory
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-59439/ - () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-59439/ - Not Applicable
CPE cpe:2.3:a:quickheal:total_security:23.0.0:*:*:*:*:-:*:*

04 Feb 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-269
CWE-281
CWE-552

03 Feb 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 18:16

Updated : 2026-02-11 16:06


NVD link : CVE-2025-69875

Mitre link : CVE-2025-69875

CVE.ORG link : CVE-2025-69875


JSON object : View

Products Affected

quickheal

  • total_security
CWE
CWE-269

Improper Privilege Management

CWE-281

Improper Preservation of Permissions

CWE-552

Files or Directories Accessible to External Parties