Totaldefense's vulnerability footprint centers on antivirus software, where the durable signal is concentrated around privilege-escalation and file-access control weaknesses such as incorrect permission assignment, link-following vulnerabilities, and TOCTOU race conditions. These classes reflect the elevated privileges and file-system monitoring demands inherent to endpoint security tools operating at the OS level. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Totaldefense over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13357HIGH In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\ used by caschelp.exe allows local attackers to hijack ccGUIFrm.dll, which leads to co | Sep 24, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-13356HIGH In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\bd\TDUpdate2\ used by AMRT.exe allows local attackers to | Sep 24, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-13355HIGH In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\ used by ccschedulersvc.exe allows local attackers to hij | Sep 24, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-18644MEDIUM The malware scan function in Total Defense Anti-virus 11.5.2.28 is vulnerable to a TOCTOU bug; consequently, symbolic link attacks allow privileged files to be deleted. | Oct 31, 2019 | 5.9 | 20 | NO | NO |
CVE-2019-18645MEDIUM The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowing files to be written to privileged directories. | Oct 31, 2019 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Totaldefense.
Media articles that mention a CVE ID that affects a product developed by Totaldefense — matched by CVE ID, not by vendor name.