DLL Hijacking Vulnerability in Tencent TIM Windows Client
CVE-2020-24160

7.8HIGH

Key Information:

Vendor

Tencent

Status
Vendor
CVE Published:
3 September 2020

What is CVE-2020-24160?

The Tencent TIM Windows client version 3.0.0.21315 contains a DLL hijacking vulnerability that can be exploited by attackers. This flaw enables unauthorized execution of malicious code by manipulating dynamic link library (DLL) files, potentially compromising system integrity and user data. It is essential for users to stay informed and implement appropriate security measures to protect against this threat.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.