CVE-2017-5005: Quickheal Antivirus Pro

Critical severity, CVSS 9.8. EPSS: 9.7% chance of exploitation in the next 30 days.

Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro 10.1.0.316 and earlier on OS X allows remote attackers to execute arbitrary code via a crafted LC_UNIXTHREAD.cmdsize field in a Mach-O file that is mishandled during a Security Scan (aka Custom Scan) operation.

Affected products

  • Quickheal Antivirus Pro: up to and including 10.1.0.316
  • Quickheal Internet Security: up to and including 10.1.0.316
  • Quickheal Total Security: up to and including 10.1.0.316

Published 2017-01-02. Last modified 2026-06-17.