CVE-2020-24772

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/03/2022
Last modified:
29/03/2022

Description

In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that would launch the Clash Windows client and force it to open a remote SMB share. Windows will perform NTLM authentication when opening the SMB share and that request can be relayed (using a tool like responder) for code execution (or captured for hash cracking).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:clash_project:clash:0.11.4:*:*:*:*:windows:*:*


References to Advisories, Solutions, and Tools