CVE-2011-0487: Icq

High severity, CVSS 9.3. EPSS: 2.5% chance of exploitation in the next 30 days.

ICQ 7 does not verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a crafted file that is fetched through an automatic-update mechanism.

Affected products

  • Icq Icq: version 7 only

Published 2011-01-18. Last modified 2026-06-16.