CVE-2021-33879
HIGHTencent GameLoop < 4.1.21.90 - Remote Code Execution via MITM Update Spoofing
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-33879. PoCs published by mmiszczyk.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2021-33879, a vulnerability in Tencent GameLoop's update mechanism that allows MITM attackers to execute arbitrary code via spoofed update packages. The writeup includes a step-by-step reproduction process and XML payload example.
Description
Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection. A malicious attacker in an MITM position could spoof the contents of an XML document describing an update package, replacing a download URL with one pointing to an arbitrary Windows executable. Because the only integrity check would be a comparison of the downloaded file's MD5 checksum to the one contained within the XML document, the downloaded executable would then be executed on the victim's machine.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2021-33879, a vulnerability in Tencent GameLoop's update mechanism that allows MITM attackers to execute arbitrary code via spoofed update packages. The writeup includes a step-by-step reproduction process and XML payload example.
References (2)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H