Sogou Input Method 'biz_helper' Remote Code Execution
Sogou Input Method contains a chain of three weaknesses that, if successfully exploited, could allow remote code execution. An attacker could exploit this vulnerability by convincing a user to click a specially crafted link.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Not confirmedLast checked today
- Affects
- Tencent+4 more
- Exploited
- Not confirmedNo confirmation recorded
Technical details
Affected software: Tencent, Sogou Input Method, Threat actor: UNC3569, Government, Education
References
- otx.alienvault.com ยท 6aa3c33464568cec4ec6b942 AlienVault OTX