← Back

Clash

clash

Vendor: Clash Project • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Clash Project
1Clash
Mar 12, 2025
Feb 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml).
1Clash Project
1Clash
May 21, 2025
Sep 29, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privileges and execute arbitrary commands when Service Mode is activated.
1Clash Project
1Clash
Nov 21, 2024
Mar 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Clash for Windows v0.19.8 was discovered to allow arbitrary code execution via a crafted payload injected into the Proxies name column.
1Clash Project
1Clash
Nov 21, 2024
Mar 21, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that would launch the Clash Windows client and force it to open a remote SMB share. Windows will perform...Show more
In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that would launch the Clash Windows client and force it to open a remote SMB share. Windows will perform NTLM authentication when opening the SMB share and that request can be relayed (using a tool like responder) for code execution (or captured for hash cracking).Show less