CVE-2025-63685

Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of system libraries. Specifically, the application does not validate the path or signature of [regsvr32.exe] it loads. An attacker can place a crafted malicious DLL in the application's startup directory, which will be loaded and executed when the user launches the program.
References
Configurations

No configuration.

History

21 Nov 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 9.8

20 Nov 2025, 22:16

Type Values Removed Values Added
CWE CWE-491
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

20 Nov 2025, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-20 21:16

Updated : 2025-11-21 15:15


NVD link : CVE-2025-63685

Mitre link : CVE-2025-63685

CVE.ORG link : CVE-2025-63685


JSON object : View

Products Affected

No product.

CWE
CWE-491

Public cloneable() Method Without Final ('Object Hijack')