Information Disclosure Vulnerability in Tencent WeChat Desktop Application
CVE-2021-27247
6.5MEDIUM
What is CVE-2021-27247?
An information disclosure vulnerability exists in the WXAM decoder of Tencent WeChat 2.9.5 for desktop, allowing remote attackers to potentially access sensitive user information. To exploit this vulnerability, an attacker must trick the user into visiting a malicious webpage or opening a malicious file, which invokes the flaw resulting from insufficient validation of user-supplied data. This could enable attackers to read beyond the end of an allocated buffer, presenting opportunities for further exploitation in conjunction with other vulnerabilities.
Affected Version(s)
WeChat 2.9.5 desktop version
