Description
A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects some unknown processing in the library qmudisk64.sys of the component QMUDisk Driver. The manipulation leads to uncontrolled search path. The attack must be carried out locally. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-07-13
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The qmudisk64.sys driver in Tencent PC Manager performs file lookups without properly sanitizing the search path, allowing a local attacker with write access to a searched directory to cause the driver to load a malicious DLL. Based on the description, it is inferred that the attacker must place the DLL in a directory scanned by the driver. This flaw could compromise the confidentiality, integrity, and availability of the system if exploited, as the DLL would run with the driver's elevated privileges.

Affected Systems

Tencent PC Manager version 18.1.30242.301 is affected.

Risk and Exploitability

The CVSS score of 7.3 reflects high severity, but the EPSS score is less than 1% and the flaw is not listed in the CISA KEV catalog. Exploitation requires local access, high complexity, and is considered difficult, which lowers the overall risk compared to remotely exploitable vulnerabilities. Based on the description, it is inferred that attackers would need to drop a crafted DLL into a directory that the driver scans, then trigger the driver to load it, potentially elevating privileges or compromising the system.

Generated by OpenCVE AI on August 1, 2026 at 11:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict write permissions on directories that qmudisk64.sys searches for DLLs to prevent unauthorized placement of malicious libraries.
  • When a vendor update addressing the issue becomes available, apply it promptly; meanwhile, monitor the vendor’s website or known vulnerability databases for patch notices.
  • Implement file integrity monitoring on the directories scanned by the driver to detect and alert on unexpected DLLs that may indicate an attempted hijack.

Generated by OpenCVE AI on August 1, 2026 at 11:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects some unknown processing in the library qmudisk64.sys of the component QMUDisk Driver. The manipulation leads to uncontrolled search path. The attack must be carried out locally. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Tencent PC Manager QMUDisk Driver qmudisk64.sys uncontrolled search path
First Time appeared Tencent
Tencent pc Manager
Weaknesses CWE-426
CWE-427
CPEs cpe:2.3:a:tencent:pc_manager:*:*:*:*:*:*:*:*
Vendors & Products Tencent
Tencent pc Manager
References
Metrics cvssV2_0

{'score': 6, 'vector': 'AV:L/AC:H/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7, 'vector': 'CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Tencent Pc Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-15T15:34:37.479Z

Reserved: 2026-07-12T11:02:05.805Z

Link: CVE-2026-15515

cve-icon Vulnrichment

Updated: 2026-07-15T15:34:10.298Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:15:03Z

Weaknesses
  • CWE-426

    Untrusted Search Path

  • CWE-427

    Uncontrolled Search Path Element