PT-2022-8696 · Dreamacro · Dreamacro Clash For Windows+1

Published

2022-03-21

·

Updated

2022-03-29

·

CVE-2020-24772

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dreamacro Clash for Windows version 0.11.4 Dreamacro version 1.1.0
Description The issue allows an attacker to embed a malicious iframe in a website with a crafted URL, launching the Clash Windows client and forcing it to open a remote SMB share. When opening the SMB share, Windows performs NTLM authentication, and this request can be relayed for code execution or captured for hash cracking.
Recommendations For Dreamacro Clash for Windows version 0.11.4, consider disabling the automatic launch of the Clash Windows client from crafted URLs as a temporary workaround until a patch is available. For Dreamacro version 1.1.0, restrict access to remote SMB shares to minimize the risk of exploitation.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24772

Affected Products

Dreamacro
Dreamacro Clash For Windows