In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-process communication, which leads to a write-what-where condition.
The product attempts to return a memory resource to the system, but it calls the wrong release function or calls the appropriate release function incorrectly.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tencent | 9.7.1.28940 (including) | 9.7.8.29039 (including) | |
Tim | Tencent | 3.4.5.22071 (including) | 3.4.7.22084 (including) |
This weakness can take several forms, such as: