VYPR
Unrated severityNVD Advisory· Published Aug 13, 2020· Updated Aug 4, 2024

CVE-2020-16087

CVE-2020-16087

Description

VNG Zalo Desktop 19.8.1.0 allows remote code execution via a crafted file sent to a user.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

VNG Zalo Desktop 19.8.1.0 allows remote code execution via a crafted file sent to a user.

Vulnerability

An issue was discovered in Zalo.exe in VNG Zalo Desktop version 19.8.1.0. The vulnerability allows an attacker to run arbitrary commands on a remote Windows machine running the Zalo client by sending the user a crafted file [1]. The exact component and file format are not detailed in the available reference, but the attack vector is through file transfer within the application.

Exploitation

An attacker sends a specially crafted file to a Zalo Desktop user. The user must open or interact with the file within the Zalo client for the exploit to trigger. No authentication or special network position is required beyond being able to send a file through Zalo. The reference does not provide a detailed sequence of steps.

Impact

Successful exploitation allows the attacker to execute arbitrary commands on the victim's Windows machine. The attacker gains code execution at the privilege level of the Zalo Desktop process, which may allow full compromise of the system.

Mitigation

As of the publication date (2020-08-13), no patch or fixed version has been disclosed in the available references. Users should be cautious when opening files from untrusted contacts. The vendor has not announced a mitigation or workaround [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • VNG Zalo/Zalo Desktopdescription
  • VNG/Zalo Desktopllm-create
    Range: = 19.8.1.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.