ZeroHour

CVE-2022-40126

PoC
CVSS 3.1
7.8 high
EPSS
<1%p24
Published
()
Modified
Description

A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privileges and execute arbitrary commands when Service Mode is activated.

Vendors
clash project
Products
clash
Weakness
CWE-552
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.