360 Total Security
Vendor:
First CVE: Aug 7, 2017 · Active for 8 years
7
Total CVEs
More Total CVEs than 83% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact 360 Total Security over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 7, 2017
8 years ago
Most Recent CVE
Apr 15, 2024
830 days ago
CVE Severity & Scoring
360 Total Security7 CVEs
14%
86%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local6 (85.7%)
Network1 (14.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (14.3%)
Unknown0 (0.0%)
Required6 (85.7%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None6 (85.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12653HIGH 360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege Escalation via a Trojan horse Shcore.dll file in any directory in the PATH, as demonstrated by the C:\Python27 dire | Aug 7, 2017 | 7.8 | 29 | NO | YES |
CVE-2020-15724HIGH In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could | Jul 21, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-15723HIGH In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome.exe, there exists a local privilege escalation vulnerabilit | Jul 21, 2020 | 7.8 | 25 | NO | NO |
CVE-2021-33973HIGH Buffer Overflow vulnerability in Qihoo 360 Safe guard v12.1.0.1004, v12.1.0.1005, v13.1.0.1001 allows attacker to escalate priveleges. | Apr 19, 2023 | 7.8 | 24 | NO | NO |
CVE-2024-22014HIGH An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated privileges via Symbolic Link Follow to Arbitrary File Delete. | Apr 15, 2024 | 8.8 | 23 | NO | NO |
CVE-2020-15722HIGH In version 12.1.0.1004 and below of 360 Total Security,when TPI calls the browser process, there exists a local privilege escalation vulnerability. An attacker who could exploit DL | Jul 21, 2020 | 7.8 | 22 | NO | NO |
CVE-2018-18603MEDIUM 360 Total Security 3.5.0.1033 allows a Sandbox Escape via an "import os" statement, followed by os.system("CMD") or os.system("PowerShell"), within a .py file. NOTE: the vendor's p | Oct 23, 2018 | 6.3 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
14.3% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For 360 Total Security
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.5.0.1033 | 1 | 6.3 | 0.9% | 0 | 0 |
| 10.8.0.1213 | 1 | 7.8 | 0.4% | 0 | 0 |