PT-2023-12233 · Qihoo 360 · 360 Safe Browser+3
Memorycorruptor
·
Published
2023-04-19
·
Updated
2023-05-04
·
CVE-2021-33971
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Qihoo 360 Safeguard versions 12.1.0.1004 through 13.1.0.1001
Qihoo 360 Total Security versions 10.8.0.1060 through 10.8.0.1213
360 Safe Browser & 360 Chrome version 13.0.2170.0
Description
The issue is a buffer overflow that allows for the execution of arbitrary code locally. This set of vulnerabilities affects popular software from Qihoo 360, including their PC client and security browsers. The attack vector involves either opening a link to exploit the vulnerability remotely via the browser or locally executing a vulnerability exploitation program on the client software. The combination of remote and local vulnerabilities can lead to an escalation of privileges and make spyware persistent on the target computer without being detected by Qihoo 360's antivirus. The vulnerabilities have been reported by a security expert and fixed by the vendor.
Recommendations
For Qihoo 360 Safeguard versions 12.1.0.1004 through 13.1.0.1001, update to a version that includes the fix for the buffer overflow vulnerability.
For Qihoo 360 Total Security versions 10.8.0.1060 through 10.8.0.1213, update to a version that includes the fix for the buffer overflow vulnerability.
For 360 Safe Browser & 360 Chrome version 13.0.2170.0, update to a version that includes the fix for the buffer overflow vulnerability.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
360 Chrome
360 Safe Browser
Qihoo 360 Safeguard
Qihoo 360 Total Security