Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mmiszczyk

#31692of 53,624
8.1Total CVSS
Vulnerabilities · 1
PT-2021-20347
8.1
2021-06-06
Tencent · Tencent Gameloop · CVE-2021-33879
Name of the Vulnerable Software and Affected Versions: Tencent GameLoop versions prior to 4.1.21.90 Description: The issue allows a malicious attacker in a man-in-the-middle (MITM) position to spoof the contents of an XML document describing an update package. This can replace a download URL with one pointing to an arbitrary Windows executable. Since the only integrity check is a comparison of the downloaded file's MD5 checksum to the one contained within the XML document, the downloaded executable would then be executed on the victim's machine. Recommendations: For versions prior to 4.1.21.90, update to version 4.1.21.90 or later to resolve the issue. As a temporary workaround, consider restricting access to the update mechanism to minimize the risk of exploitation. Avoid using insecure HTTP connections for downloading updates until the issue is resolved.