Executive brief
QND is a Windows client application used for secure network communication and credential management. A local user logged into a Windows PC with QND installed can exploit an improperly protected named pipe to execute arbitrary commands with SYSTEM-level privileges, effectively gaining full administrative control of the machine.
Technical details
CVE-2026-84408 is an improper access control vulnerability (CWE-782) in a Windows named pipe used by QND. A local attacker with user-level login access can leverage this to execute arbitrary commands with SYSTEM privileges. The vulnerability requires only local access and no additional authentication; patches are available through the vendor's customer portal.
Affected products
- QualitySoft QND Premium 11.1i and earlier
- QualitySoft QND Standard 11.1i and earlier
- QualitySoft QND Advance 11.0.9i and earlier
Timeline
- 2026-09-16: disclosed