360totalsecurity's vulnerability profile concentrates in its flagship antivirus and system-utility product, which operates at a privileged level with deep system integration that exposes it to local-escalation and path-traversal attack surfaces. The recurring weakness classes—uncontrolled search paths, classic buffer overflows, and symlink-following conditions—reflect the memory-safety and file-system interaction risks inherent to system-level security software, and public exploit code has frequently been developed for this vendor's disclosures. Current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 360totalsecurity over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12653HIGH 360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege Escalation via a Trojan horse Shcore.dll file in any directory in the PATH, as demonstrated by the C:\Python27 dire | Aug 7, 2017 | 7.8 | 29 | NO | YES |
CVE-2020-15724HIGH In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could | Jul 21, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-15723HIGH In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome.exe, there exists a local privilege escalation vulnerabilit | Jul 21, 2020 | 7.8 | 25 | NO | NO |
CVE-2021-33973HIGH Buffer Overflow vulnerability in Qihoo 360 Safe guard v12.1.0.1004, v12.1.0.1005, v13.1.0.1001 allows attacker to escalate priveleges. | Apr 19, 2023 | 7.8 | 24 | NO | NO |
CVE-2024-22014HIGH An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated privileges via Symbolic Link Follow to Arbitrary File Delete. | Apr 15, 2024 | 8.8 | 23 | NO | NO |
CVE-2020-15722HIGH In version 12.1.0.1004 and below of 360 Total Security,when TPI calls the browser process, there exists a local privilege escalation vulnerability. An attacker who could exploit DL | Jul 21, 2020 | 7.8 | 22 | NO | NO |
CVE-2018-18603MEDIUM 360 Total Security 3.5.0.1033 allows a Sandbox Escape via an "import os" statement, followed by os.system("CMD") or os.system("PowerShell"), within a .py file. NOTE: the vendor's p | Oct 23, 2018 | 6.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 360totalsecurity.
Media articles that mention a CVE ID that affects a product developed by 360totalsecurity — matched by CVE ID, not by vendor name.