June 1, 2023, 3:15 a.m. |

National Vulnerability Database web.nvd.nist.gov

In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-process communication, which leads to a write-what-where condition.

communication cve dll process tencent tim

Application Security Assurance Associate

@ DTCC | Tampa, FL, United States

Threat Hunter II

@ Microsoft | Hyderabad, Telangana, India

Staff Cyber Security Engineer (Application Security, Emerging Platforms)

@ NBCUniversal | Englewood Cliffs, NEW JERSEY, United States

Cyber Security Senior Cyber Security Engineer

@ Sopra Steria | Noida, Uttar Pradesh, India

Data Protection and Privacy Manager

@ Future PLC | London, England, United Kingdom

RSOC Manager

@ The University of Texas at Austin | AUSTIN, TX