CVE-2025-69875

A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to restore quarantined files into protected system directories. This behavior can be abused by a local attacker to place files in high-privilege locations, potentially leading to privilege escalation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:quickheal:total_security:23.0.0:*:*:*:*:-:*:*

History

17 Jun 2026, 10:00

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad existe en Quick Heal Total Security 23.0.0 en el componente de gestión de cuarentena, donde la validación insuficiente de las rutas de restauración y el manejo inadecuado de permisos permiten a un usuario local con pocos privilegios restaurar archivos en cuarentena en directorios del sistema protegidos. Este comportamiento puede ser abusado por un atacante local para colocar archivos en ubicaciones de alto privilegio, lo que podría conducir a una escalada de privilegios.

11 Feb 2026, 16:06

Type Values Removed Values Added
First Time Quickheal total Security
Quickheal
References () https://github.com/mertdas/QuickHealTotalSecurityPOC - () https://github.com/mertdas/QuickHealTotalSecurityPOC - Third Party Advisory
References () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-59439/ - () https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2025-59439/ - Not Applicable
CPE cpe:2.3:a:quickheal:total_security:23.0.0:*:*:*:*:-:*:*

04 Feb 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-269
CWE-281
CWE-552

03 Feb 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 18:16

Updated : 2026-06-17 10:00


NVD link : CVE-2025-69875

Mitre link : CVE-2025-69875

CVE.ORG link : CVE-2025-69875


JSON object : View

Products Affected

quickheal

  • total_security
CWE
CWE-269

Improper Privilege Management

CWE-281

Improper Preservation of Permissions

CWE-552

Files or Directories Accessible to External Parties