Back to overview

CVE-2026-12214

HIGH Exploitation: PoC
7.8
CVSS 3.1
Description
A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the function RpcStringBindingComposeW of the component Nucleus Engine Monitoring Logic. Performing a manipulation of the argument NetworkAddr results in protection mechanism failure. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Metadata

CVE ID
CVE-2026-12214
State
PUBLISHED
Assigner
VulDB
Reserved
2026-06-14 12:54 UTC
Published
2026-06-15 03:30 UTC
Last updated
2026-06-15 12:51 UTC
Primary CWE
CWE-693
Protection Mechanism Failure
Vendor / Product
Qihoo / 360 Total Security
Sources
cve.org  ·  NVD

Severity & Metrics

7.8 HIGH CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Qihoo 360 Total Security 6.0
Weakness (CWE)
CWESourceDescription
CWE-693 cna Protection Mechanism Failure
CVSS scores (4)
ScoreSeverityVersionSourceVector
8.5 HIGH 4.0 cna CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
7.8 HIGH 3.1 cna CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
7.8 HIGH 3.0 cna CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
6.8 N/D 2.0 cna AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR
References (5)
Back to overview