Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-24772

Опубликовано: 21 мар. 2022
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that would launch the Clash Windows client and force it to open a remote SMB share. Windows will perform NTLM authentication when opening the SMB share and that request can be relayed (using a tool like responder) for code execution (or captured for hash cracking).

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:clash_project:clash:0.11.4:*:*:*:*:windows:*:*

EPSS

Процентиль: 31%
0.00121
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 8.8
github
почти 4 года назад

In Dreamacro 1.1.0, an attacker could embed a malicious iframe in a website with a crafted URL that would launch the Clash Windows client and force it to open a remote SMB share. Windows will perform NTLM authentication when opening the SMB share and that request can be relayed (using a tool like responder) for code execution (or captured for hash cracking).

EPSS

Процентиль: 31%
0.00121
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-346