CVE-2024-57394

The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. Attackers can write malicious DLL to system path and perform privilege escalation by leveraging Windows DLL hijacking vulnerabilities.
Configurations

No configuration.

History

12 May 2025, 15:15

Type Values Removed Values Added
CWE CWE-73
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

23 Apr 2025, 14:08

Type Values Removed Values Added
Summary
  • (es) quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 permite restaurar un archivo malicioso en una ruta de acceso arbitraria. Los atacantes pueden escribir DLL maliciosas en la ruta del sistema y escalar privilegios aprovechando las vulnerabilidades de secuestro de DLL de Windows.

21 Apr 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-21 18:15

Updated : 2025-05-12 15:15


NVD link : CVE-2024-57394

Mitre link : CVE-2024-57394

CVE.ORG link : CVE-2024-57394


JSON object : View

Products Affected

No product.

CWE
CWE-73

External Control of File Name or Path