Critical severity9.8NVD Advisory· Published Nov 20, 2025· Updated Jun 17, 2026
CVE-2025-63685
CVE-2025-63685
Description
Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of system libraries. Specifically, the application does not validate the path or signature of [regsvr32.exe] it loads. An attacker can place a crafted malicious DLL in the application's startup directory, which will be loaded and executed when the user launches the program.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: =3.23.2
(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:quark:quark_cloud_drive:3.23.2:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/QIU-DIE/CVE/issues/5nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.