A vulnerability exists in Tencent QQ (through 9.7.8.29039) and TIM (through 3.4.7.22084) within the QQProtect.exe and QQProtectEngine.dll components. These components fail to properly validate pointers received via inter-process communication, resulting in a write-what-where condition. This allows an attacker to control both the data written and the destination address in memory, potentially leading to arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a local privilege escalation exploit targeting Tencent QQ and TIM instant messaging software on Windows. The exploit leverages two arbitrary address write vulnerabilities in QQProtect.exe and QQProtectEngine.dll, components installed as a SYSTEM service. The exploit is implemented in Rust and consists of two main DLLs: tinyxml.dll (the exploit orchestrator) and evil.dll (the payload). The exploit works by communicating with QQProtect via named pipes, manipulating memory to hijack function pointers, and ultimately loading the attacker's evil.dll into the QQProtect.exe process. The evil.dll payload duplicates the SYSTEM token and spawns a SYSTEM-level cmd.exe shell. The repository includes Rust source code, build scripts, and sample binaries for the targeted QQ and TIM versions. The attack is local and requires the attacker to have the ability to execute code on the target system, but results in full SYSTEM privileges if successful.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.