CVE-2023-34312
HIGH 7.8EPSS 0.6%
In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-process communication, which leads to a write-what-where condition.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 0.60% chance of exploitation in the next 30 days, 46th percentile
- Published
- 2023-06-01
- Updated
- 2025-01-09
Proof-of-concept exploits (2)
- vi3t1/qq-tim-elevation419★ · 2023-05-27
- lan1oc/CVE-2023-34312-exp8★ · 2023-08-10