Vulnerability Description
The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. This affects Total Security, Home Security, Total Security Multi-Device, Internet Security, Total Security for Mac, AntiVirus Pro, AntiVirus for Server, and Total Security for Android.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Quickheal | Antivirus For Server | 2019-11 |
| Quickheal | Antivirus Pro | 2019-11 |
| Quickheal | Home Security | 2019-11 |
| Quickheal | Internet Security | 2019-11 |
| Quickheal | Total Security | 2019-11 |
| Quickheal | Total Security Multi-Device | 2019-11 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/156580/QuickHeal-Generic-Malformed-Archive-Third Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Mar/14Mailing ListThird Party Advisory
- https://blog.zoller.lu/p/from-low-hanging-fruit-department_24.htmlThird Party Advisory
- https://blog.zoller.lu/p/tzo-20-2020-quickheal-malformed-archive.htmlThird Party Advisory
- http://packetstormsecurity.com/files/156580/QuickHeal-Generic-Malformed-Archive-Third Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Mar/14Mailing ListThird Party Advisory
- https://blog.zoller.lu/p/from-low-hanging-fruit-department_24.htmlThird Party Advisory
- https://blog.zoller.lu/p/tzo-20-2020-quickheal-malformed-archive.htmlThird Party Advisory
FAQ
What is CVE-2020-9362?
CVE-2020-9362 is a vulnerability with a CVSS score of 7.8 (HIGH). The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. This affects Total Security, Home Security, Total Security Multi-Device, Internet ...
How severe is CVE-2020-9362?
CVE-2020-9362 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9362?
Check the references section above for vendor advisories and patch information. Affected products include: Quickheal Antivirus For Server, Quickheal Antivirus Pro, Quickheal Home Security, Quickheal Internet Security, Quickheal Total Security.