Security ID : QSA-25-47
Vulnerability in Malware Remover (PWN2OWN 2025)
Release date : November 8, 2025
CVE identifier : CVE-2025-11837 | ZDI-CAN-28324
Affected products: Malware Remover 6.6.x
Severity
Critical
Status
Resolved
Summary
An improper control of generation of code vulnerability has been reported to affect Malware Remover. If exploited, the vulnerability could allow remote attackers to bypass protection mechanisms and execute arbitrary code.
| Affected Product | Fixed Version |
| Malware Remover 6.6.x | Malware Remover 6.6.8.20251023 and later |
Recommendation
To fix the vulnerability, we recommend updating Malware Remover to the latest version.
Updating Malware Remover
- Log on to QTS or QuTS hero as an administrator.
- Open App Center and then click
.
A search box appears. - Type "Malware Remover" and then press ENTER.
Malware Remover appears in the search results. - Click Update.
A confirmation message appears.
Note: The Update button is not available if your Malware Remover is already up to date. - Click OK.
The system updates the application.
Attachment
Acknowledgements: CyCraft Technology Intern
Revision History:
V1.0 (November 8, 2025) - Published
V1.1 (January 3, 2026) - Added more details