Vulnerability Description
QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe. This file is writable by anyone belonging to the NT AUTHORITY\Authenticated Users group, which includes all local and remote users. This can be abused by local attackers to escalate privileges to NT AUTHORITY\SYSTEM by writing a malicious executable to the location of TsService.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tencent | Qqbrowser | < 10.5.3870.400 |
Related Weaknesses (CWE)
References
- https://github.com/seqred-s-a/CVE-2020-10551Third Party Advisory
- https://seqred.pl/en/cve-2020-10551-privilege-escalation-in-qqbrowser/Third Party Advisory
- https://github.com/seqred-s-a/CVE-2020-10551Third Party Advisory
- https://seqred.pl/en/cve-2020-10551-privilege-escalation-in-qqbrowser/Third Party Advisory
FAQ
What is CVE-2020-10551?
CVE-2020-10551 is a vulnerability with a CVSS score of 7.8 (HIGH). QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe. This file is writable by anyone belonging to the NT AUTHORITY\Authenticated Users group, which includes all local and remote us...
How severe is CVE-2020-10551?
CVE-2020-10551 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10551?
Check the references section above for vendor advisories and patch information. Affected products include: Tencent Qqbrowser.