Vulnerability Description
A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to restore quarantined files into protected system directories. This behavior can be abused by a local attacker to place files in high-privilege locations, potentially leading to privilege escalation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Quickheal | Total Security | 23.0.0 |
Related Weaknesses (CWE)
References
- https://github.com/mertdas/QuickHealTotalSecurityPOCThird Party Advisory
- https://semiconductor.samsung.com/support/quality-support/product-security-updatNot Applicable
FAQ
What is CVE-2025-69875?
CVE-2025-69875 is a vulnerability with a CVSS score of 7.8 (HIGH). A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged...
How severe is CVE-2025-69875?
CVE-2025-69875 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-69875?
Check the references section above for vendor advisories and patch information. Affected products include: Quickheal Total Security.