VYPR
High severity7.9NVD Advisory· Published May 23, 2022· Updated Jun 17, 2026

CVE-2022-31466

CVE-2022-31466

Description

Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, potentially leading to deletion of system files. This is achieved through exploiting the time between detecting a file as malicious and when the action of quarantining or cleaning is performed, and using the time to replace the malicious file by a symlink.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Quickheal/Total Securitycpe-rescue3 versions
    (expand)+ 2 more
    • (no CPE)
    • cpe:2.3:a:quickheal:total_security:*:*:*:*:*:*:*:*range: <12.1.1.27
    • (no CPE)range: <=12.1.1.27

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.