Home

Description

Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of system libraries. Specifically, the application does not validate the path or signature of [regsvr32.exe] it loads. An attacker can place a crafted malicious DLL in the application's startup directory, which will be loaded and executed when the user launches the program.

PUBLISHED Reserved 2025-10-27 | Published 2025-11-20 | Updated 2025-11-21 | Assigner mitre

References

github.com/QIU-DIE/CVE/issues/5

cve.org (CVE-2025-63685)

nvd.nist.gov (CVE-2025-63685)

Download JSON