In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-process communication, which leads to a write-what-where condition.
2023-06-01T03:15:20.673
2025-01-09T17:15:10.757
Modified
CVSSv3.1: 7.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | tencent | ≤ 9.7.8.29039 | Yes | |
Application | tencent | tim | ≤ 3.4.7.22084 | Yes |