Lucene search

K
prionPRIOn knowledge basePRION:CVE-2020-24772
HistoryMar 21, 2022 - 3:15 p.m.

Open redirect

2022-03-2115:15:00
PRIOn knowledge base
www.prio-n.com
2

8.8 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.2%

In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that would launch the Clash Windows client and force it to open a remote SMB share. Windows will perform NTLM authentication when opening the SMB share and that request can be relayed (using a tool like responder) for code execution (or captured for hash cracking).

CPENameOperatorVersion
clasheq0.11.4

8.8 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.2%

Related for PRION:CVE-2020-24772