CVE-2023-34312
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Jun 1, 2023
Updated: Jan 9, 2025
CWE ID 763
Summary
CVE-2023-34312 is a vulnerability affecting Tencent QQ version 9.7.8.29039 and TIM version 3.4.7.22084. The issue lies within the QQProtect.exe and QQProtectEngine.dll components, which fail to validate pointers during inter-process communication. This flaw creates a write-what-where condition, allowing an attacker to potentially manipulate data in unintended locations, leading to potential code execution or denial-of-service attacks. Users are advised to update their software as soon as patches become available to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.