RSS   Vulnerabilities for 'Qqbrowser'   RSS

2020-04-09
 
CVE-2020-10551

CWE-269
 

 
QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe. This file is writable by anyone belonging to the NT AUTHORITY\Authenticated Users group, which includes all local and remote users. This can be abused by local attackers to escalate privileges to NT AUTHORITY\SYSTEM by writing a malicious executable to the location of TsService.

 

 >>> Vendor: Tencent 12 Products
Foxmail
Qqpimsecure
Mobileqq
Microblogpad
Wblog
Qqpphoto
Wechat pay
Wechat
Habomalhunter
Qqbrowser
Tencent
TIM


Copyright 2024, cxsecurity.com

 

Back to Top