CVE-2021-33879 describes a critical vulnerability in Tencent GameLoop before version 4.1.21.90, where the application downloaded updates over an insecure HTTP connection. An attacker in a Man-in-the-Middle (MITM) position could exploit this by spoofing update XML documents, replacing legitimate download URLs with links to malicious Windows executables. The vulnerability carries a CVSS score of 8.1 (HIGH), indicating a high potential for impact (confidentiality, integrity, and availability) with high attack complexity, as the only integrity check was an easily manipulated MD5 checksum. While no active exploitation, public exploit code, or significant community discussion has been observed, the nature of the flaw allows for remote code execution on affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.1.21.90CPE matchmatch criteria | cpe:2.3:a:tencent:gameloop:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.