Quark Cloud Drive v3.23.2 has a DLL Hijacking...
High severity
Unreviewed
Published
Nov 20, 2025
to the GitHub Advisory Database
•
Updated Nov 21, 2025
Description
Published by the National Vulnerability Database
Nov 20, 2025
Published to the GitHub Advisory Database
Nov 20, 2025
Last updated
Nov 21, 2025
Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of system libraries. Specifically, the application does not validate the path or signature of [regsvr32.exe] it loads. An attacker can place a crafted malicious DLL in the application's startup directory, which will be loaded and executed when the user launches the program.
References