vendor:
QQPlayer
by:
James Ritchey
7,8
CVSS
HIGH
Heap Pointer Overwrite
119
CWE
Product Name: QQPlayer
Affected Version From: 3.7.892
Affected Version To: 3.7.892
Patch Exists: YES
Related CWE: N/A
CPE: a:qq-player:qqplayer
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2012
QQPlayer 3.7.892 m2p quartz.dll heap pointer overwrite PoC
QQPlayer 3.7.892 is vulnerable to a heap pointer overwrite vulnerability. An attacker can craft a malicious .m2p file and send it to the victim. When the victim opens the file, the heap pointer overwrite will occur, allowing the attacker to execute arbitrary code.
Mitigation:
Users should avoid opening untrusted files, and should update to the latest version of QQPlayer.