Lucene search

K
osvGoogleOSV:CVE-2020-24772
HistoryMar 21, 2022 - 3:15 p.m.

CVE-2020-24772

2022-03-2115:15:00
Google
osv.dev
2

7.8 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

61.2%

In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that would launch the Clash Windows client and force it to open a remote SMB share. Windows will perform NTLM authentication when opening the SMB share and that request can be relayed (using a tool like responder) for code execution (or captured for hash cracking).

7.8 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

61.2%

Related for OSV:CVE-2020-24772