CVE-2020-15723

HIGH

360totalsecurity 360 Total Security - Uncontrolled Search Path

Title source: rule

Description

In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking to bypass the hips could execute arbitrary code on the Local system.

Scores

CVSS v3 7.8
EPSS 0.0005
EPSS Percentile 14.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (1)

360totalsecurity/360_total_security < 12.1.0.1004

Timeline

Published Jul 21, 2020
Tracked Since Feb 18, 2026