PT-2023-12233 · Qihoo 360 · 360 Safe Browser+3

Memorycorruptor

·

Published

2023-04-19

·

Updated

2023-05-04

·

CVE-2021-33971

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Qihoo 360 Safeguard versions 12.1.0.1004 through 13.1.0.1001 Qihoo 360 Total Security versions 10.8.0.1060 through 10.8.0.1213 360 Safe Browser & 360 Chrome version 13.0.2170.0
Description The issue is a buffer overflow that allows for the execution of arbitrary code locally. This set of vulnerabilities affects popular software from Qihoo 360, including their PC client and security browsers. The attack vector involves either opening a link to exploit the vulnerability remotely via the browser or locally executing a vulnerability exploitation program on the client software. The combination of remote and local vulnerabilities can lead to an escalation of privileges and make spyware persistent on the target computer without being detected by Qihoo 360's antivirus. The vulnerabilities have been reported by a security expert and fixed by the vendor.
Recommendations For Qihoo 360 Safeguard versions 12.1.0.1004 through 13.1.0.1001, update to a version that includes the fix for the buffer overflow vulnerability. For Qihoo 360 Total Security versions 10.8.0.1060 through 10.8.0.1213, update to a version that includes the fix for the buffer overflow vulnerability. For 360 Safe Browser & 360 Chrome version 13.0.2170.0, update to a version that includes the fix for the buffer overflow vulnerability.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2021-33971

Affected Products

360 Chrome
360 Safe Browser
Qihoo 360 Safeguard
Qihoo 360 Total Security