---
id: CVE-2026-15515
title: >-
  A security vulnerability has been detected in Tencent PC Manager
  18.1.30242.301
summary: >-
  A security vulnerability has been detected in Tencent PC Manager
  18.1.30242.301. This issue affects some unknown processing in the library
  qmudisk64.sys of the component QMUDisk Driver. The manipulation leads to
  uncontrolled search path.…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-426
  - CWE-427
published: '2026-07-13'
updated: '2026-07-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15515'
references:
  - url: 'https://github.com/subsubsub1231/qmukiller'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-15515'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/848643'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/377844'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/377844/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-07-13T01:23:10.972Z'
epss: 0.0016
epssPercentile: 0.05584
---

## Overview

A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects some unknown processing in the library qmudisk64.sys of the component QMUDisk Driver. The manipulation leads to uncontrolled search path. The attack must be carried out locally. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
