CVE-2020-15723

HIGH

360 Total Security < 12.1.0.1004 - Local Privilege Escalation via DLL Hijacking

Title source: llm
STIX 2.1

Description

In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking to bypass the hips could execute arbitrary code on the Local system.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://security.360.cn/News/news/id/232

Scores

CVSS v3 7.8
EPSS 0.0048
EPSS Percentile 37.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-427
Status published
Products (1)
360totalsecurity/360_total_security < 12.1.0.1004
Published Jul 21, 2020
Tracked Since Feb 18, 2026