CVE-2026-12214 Details
Description
A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the function RpcStringBindingComposeW of the component Nucleus Engine Monitoring Logic. Performing a manipulation of the argument NetworkAddr results in protection mechanism failure. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
A security bypass vulnerability has been identified in Qihoo 360 Total Security version 6.0, specifically within the Nucleus Engine Monitoring Logic. This vulnerability arises in the RpcStringBindingComposeW function, where the NetworkAddr parameter can be manipulated to bypass the engine's protection mechanisms. The issue allows for the creation of scheduled tasks via the Windows Task Scheduler RPC interface, without triggering any alerts from the Nucleus Engine. The vulnerability requires local execution and has been publicly disclosed, with an exploit available.
Users are advised to enhance the monitoring of RPC bindings to include all representations of local addresses, implement deep inspection of RPC payloads for malicious task content, and improve auditing and logging of RPC-based task creation events.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 15, 2026CISA-ADP
Assessed Jun 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Gach0ng/vuldb_submit/issues/4 | [email protected] | ExploitIssue TrackingTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-12214 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/833135 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/370858 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/370858/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-693 | Protection Mechanism Failure | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Qihoo 360 Total Security | All versions |
CPE
Remediation
| |
| Microsoft Windows | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 15, 2026 | New CVE Received | [email protected] |
Volerion