Get the App
SLTechnology News&Howtos  ›  IT Information  › 

Windows QQ client version 9.7.13 remote code execution vulnerability, official emergency update fix

Shulou Source: shulou.com Published: 2023-11-24 18:54:50 10月06日 Update

Thanks to CTOnews.com netizens Alejandro86, soft media users 1520111, Edmund Tang Tess, my love 317, Neko_233, Gincox for the delivery of clues! CTOnews.com August 21 news, Cyber Kunlun, a well-known domestic network security company, today reported a high-risk security loophole in the Windows version of Tencent QQ desktop client, which is said to be "extremely difficult and harmful for hackers". Tencent has just urgently released version 9.7.15 QQ to fix the vulnerability.

It is reported that the attacker only needs to construct an extremely simple message link, and when a user clicks the message link in a QQ friend or QQ group, QQ will automatically download and open the malicious file.

CTOnews.com learned that this vulnerability affects QQ 9.7.13 and previous versions of Windows. Tencent has urgently released Windows version (traditional version) QQ 9.7.15, which has solved the problem. CTOnews.com friends can download it here.

The QQ NT version is not affected by this vulnerability, but considering that the NT version QQ uses the Electron architecture, some users reject this version of QQ and prefer to use the traditional version of QQ, so if these users have not updated the latest QQ version, it is not appropriate to click on any unknown network links in the chat window.

Tags: Version vulnerability user message link Tencent security tradition company network problem impact customer client update well-known big one skylight friend Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Technology Xiaomi Apple Docker MariaDB