Qsee Client Insecure DLL Loading Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability exists in the installer for Qsee Client versions 1.0.1 and prior, due to insecure loading of Dynamic Link Libraries (DLLs). This flaw allows arbitrary code to be executed with administrative privileges. The issue arises when a user is instructed to place a malicious DLL in the same directory as the installer and then run the installer.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution with administrative privileges.

Remediation

Qsee has stated that the product is no longer under development and recommends users discontinue its use.

Added: Mar 9, 2026, 6:19 AM
Updated: Mar 9, 2026, 6:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.2
remediation
0.0
relevance
3.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.