HIGH 7.8

CVE-2026-12214: Qihoo 360 Total Security 6.0 Protection Bypass Vulnerability

Qihoo 360 Total Security version 6.0 contains a vulnerability in its Nucleus Engine Monitoring Logic that allows a local attacker with regular user privileges to bypass security protections by manipulating how the system handles network address parameters. This flaw has been publicly disclosed with working exploit code available, creating immediate risk for organizations running this software.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.8 HIGH · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-693
Affected products
0 configuration(s)
Published / Modified
2026-06-15 / 2026-06-17

NVD description (verbatim)

A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the function RpcStringBindingComposeW of the component Nucleus Engine Monitoring Logic. Performing a manipulation of the argument NetworkAddr results in protection mechanism failure. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

5 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-12214 is a protection mechanism failure (CWE-693) in the RpcStringBindingComposeW function within Qihoo 360 Total Security 6.0's Nucleus Engine Monitoring Logic. The vulnerability stems from improper validation of the NetworkAddr argument, enabling a local attacker to subvert security controls. The attack requires only standard user-level access and no user interaction, making it straightforward to exploit once an attacker gains local system access.

Business impact

Organizations deploying Qihoo 360 Total Security 6.0 face elevated insider threat and privilege escalation risks. An attacker with local access—whether through a secondary compromise, contractor, or malicious employee—can bypass the product's protective mechanisms to achieve high-impact outcomes including unauthorized data access, system modification, or service disruption. This is particularly concerning in environments where 360 Total Security is relied upon as a primary defense layer.

Affected systems

Qihoo 360 Total Security version 6.0 is explicitly affected. Organizations should verify whether they are running this specific version and identify all systems where it is deployed, particularly security-critical infrastructure, endpoint devices, and systems handling sensitive data.

Exploitability

Exploitability is high. Public exploit code is available, the attack requires only local access and standard user privileges (no administrator rights needed), and no user interaction is necessary for successful exploitation. The CVSS 3.1 score of 7.8 (HIGH) reflects these favorable conditions for an attacker. Threat actors can weaponize this flaw with minimal effort.

Remediation

Immediate action is required. Contact Qihoo (360 Security) to obtain a patched version of Total Security—verify patch availability directly with the vendor, as the vendor has not yet publicly acknowledged this disclosure despite early notification. As an interim measure, restrict local access privileges where possible, apply least-privilege principles to user accounts, and monitor for suspicious process behavior within the Nucleus Engine component.

Patch guidance

Check the official Qihoo 360 website and vendor support channels for a patched build of Total Security that addresses this RpcStringBindingComposeW vulnerability. Given the vendor's apparent lack of response to early disclosure, obtain confirmation of patch status before upgrading. Test patches in a non-production environment first to ensure compatibility. Organizations unable to patch immediately should escalate compensating controls.

Detection guidance

Monitor for abnormal manipulation of RPC binding parameters and unexpected calls to RpcStringBindingComposeW with invalid or manipulated NetworkAddr arguments. Endpoint Detection and Response (EDR) tools should flag attempts to modify network address bindings at the user level. Log and alert on privilege escalation attempts originating from the Total Security process or its child processes. Forensic analysis should examine command-line arguments, process ancestry, and file system access patterns following any suspected exploitation.

Why prioritize this

This vulnerability merits immediate prioritization due to the combination of high impact (full confidentiality, integrity, and availability compromise), low attack complexity, public exploit availability, and vendor non-responsiveness. Any system running version 6.0 should be treated as at-risk. The barrier to exploitation is low for an attacker who already has local access, and the protection mechanism bypass undermines the security posture of the entire endpoint.

Risk score, explained

The CVSS 3.1 score of 7.8 (HIGH) reflects: (1) Local attack vector with standard user privilege requirement—common in realistic threat scenarios; (2) Low attack complexity—no special conditions needed; (3) High impact across confidentiality, integrity, and availability; (4) No user interaction required. Public exploit code and vendor non-engagement elevate practical risk beyond the base score, warranting expedited remediation.

Frequently asked questions

Does this vulnerability require administrator privileges to exploit?

No. The vulnerability can be exploited by any user with local access to the system running Qihoo 360 Total Security 6.0. Only standard user-level privileges are needed, making it accessible to a broad set of potential threat actors including low-privilege employees or compromised accounts.

Is Qihoo 360 Total Security version 7.0 or higher affected?

The vulnerability is explicitly documented for version 6.0. Organizations running other versions should verify their specific build against vendor advisories or contact Qihoo directly for confirmation of their patch status, as version-specific information was not provided in the disclosure.

What should I do if I cannot patch immediately?

Implement immediate compensating controls: (1) restrict local access and apply principle of least privilege to user accounts; (2) enable enhanced monitoring and EDR detection on endpoints running version 6.0; (3) isolate affected systems if they handle highly sensitive data; (4) establish a rapid patch deployment schedule and prioritize systems with the highest risk profile.

Why didn't the vendor respond to early notification?

The disclosure indicates the vendor was contacted early but did not respond. This lack of engagement complicates remediation timelines. Affected organizations should reach out directly to Qihoo 360 support to request patch status and escalate if necessary. This is a rare scenario; most vendors acknowledge and coordinate fixes within standard responsible disclosure windows.

This analysis is based on the CVE-2026-12214 public disclosure and CVSS 3.1 vector provided. Patch version numbers and specific remediation steps should be verified against official Qihoo 360 vendor advisories. Organizations should conduct independent risk assessment based on their deployment environment, user access controls, and security tooling. SEC.co does not endorse or distribute exploit code. This document is for informational purposes and should not substitute for vendor consultation or professional security assessment. Source: NVD (public-domain), retrieved 2026-07-20. Analysis generated by SEC.co (claude-haiku-4-5).