Junglewise Threat Intelligence

CVE-2026-15515: Tencent PC Manager uncontrolled search path in QMUDisk Driver

CVE-2026-15515 · Severity: high · CVSS 7 · Published 2026-07-13

Vendors: Tencent.

Executive brief

A security vulnerability exists in Tencent PC Manager, a suite of tools used for system security and optimization. An attacker with local access to a computer could exploit a flaw in how the software loads system files to gain elevated control over the device. This could lead to a complete system compromise, though the attack is technically difficult to execute.

Technical details

An uncontrolled search path vulnerability (CWE-427/CWE-426) exists in the QMUDisk Driver (qmudisk64.sys) of Tencent PC Manager version 18.1.30242.301. The flaw occurs during the processing of library loads, where the driver fails to properly validate or restrict the search path for required components. A local attacker with low privileges can exploit this by placing a malicious file in a location searched by the driver, leading to arbitrary code execution with kernel-level privileges. The attack is characterized by high complexity and difficult exploitability. As of the advisory date, the vendor has not responded to the disclosure.

Affected products

  • Tencent PC Manager 18.1.30242.301

Timeline

  • 2026-07-13: advisory: NVD publication date
  • 2026-07-13: disclosed: Public disclosure of the exploit

References