CVE-2020-10551

QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe. This file is writable by anyone belonging to the NT AUTHORITY\Authenticated Users group, which includes all local and remote users. This can be abused by local attackers to escalate privileges to NT AUTHORITY\SYSTEM by writing a malicious executable to the location of TsService.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tencent:qqbrowser:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:55

Type Values Removed Values Added
References () https://github.com/seqred-s-a/CVE-2020-10551 - Third Party Advisory () https://github.com/seqred-s-a/CVE-2020-10551 - Third Party Advisory
References () https://seqred.pl/en/cve-2020-10551-privilege-escalation-in-qqbrowser/ - Third Party Advisory () https://seqred.pl/en/cve-2020-10551-privilege-escalation-in-qqbrowser/ - Third Party Advisory

Information

Published : 2020-04-09 13:15

Updated : 2024-11-21 04:55


NVD link : CVE-2020-10551

Mitre link : CVE-2020-10551

CVE.ORG link : CVE-2020-10551


JSON object : View

Products Affected

tencent

  • qqbrowser
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource