PT-2022-8696 · Dreamacro · Dreamacro Clash For Windows+1
Published
2022-03-21
·
Updated
2022-03-29
·
CVE-2020-24772
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dreamacro Clash for Windows version 0.11.4
Dreamacro version 1.1.0
Description
The issue allows an attacker to embed a malicious iframe in a website with a crafted URL, launching the Clash Windows client and forcing it to open a remote SMB share. When opening the SMB share, Windows performs NTLM authentication, and this request can be relayed for code execution or captured for hash cracking.
Recommendations
For Dreamacro Clash for Windows version 0.11.4, consider disabling the automatic launch of the Clash Windows client from crafted URLs as a temporary workaround until a patch is available.
For Dreamacro version 1.1.0, restrict access to remote SMB shares to minimize the risk of exploitation.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dreamacro
Dreamacro Clash For Windows