CVE-2023-53973

HIGH

Zillya Total Security 3.0.2367.0 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-53973. PoCs published by M. Akil Gündoğan.

AI-analyzed exploit summary This is a writeup describing a local privilege escalation vulnerability in Zillya Total Security and Internet Security. The vulnerability allows low-privileged users to restore quarantined files to unauthorized locations, potentially leading to DLL hijacking and SYSTEM privilege escalation.

Description

Zillya Total Security 3.0.2367.0 contains a privilege escalation vulnerability that allows low-privileged users to copy files to unauthorized system locations using the quarantine module. Attackers can leverage symbolic link techniques to restore quarantined files to restricted directories, potentially enabling system-level access through techniques like DLL hijacking.

Exploits (1)

exploitdb WRITEUP
by M. Akil Gündoğan · textlocalwindows
https://www.exploit-db.com/exploits/51151

This is a writeup describing a local privilege escalation vulnerability in Zillya Total Security and Internet Security. The vulnerability allows low-privileged users to restore quarantined files to unauthorized locations, potentially leading to DLL hijacking and SYSTEM privilege escalation.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Zillya Total Security (3.0.2368.0) / Zillya Internet Security (3.0.2367.0)
Auth required
Prerequisites: Low-privileged user access · Zillya Total Security or Internet Security installed · Ability to create symbolic links
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/51151
Product product
https://zillya.com/

Scores

CVSS v3 8.4
EPSS 0.0022
EPSS Percentile 11.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-59
Status published
Products (1)
zillya/total_security 3.0.2367.0
Published Dec 22, 2025
Tracked Since Feb 18, 2026