Vulnerability Description
A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privileges and execute arbitrary commands when Service Mode is activated.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Clash Project | Clash | 0.19.9 |
Related Weaknesses (CWE)
References
- https://github.com/Fndroid/clash_for_windows_pkg/issues/3405ExploitIssue TrackingThird Party Advisory
- https://github.com/Fndroid/clash_for_windows_pkg/issues/3405ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2022-40126?
CVE-2022-40126 is a vulnerability with a CVSS score of 7.8 (HIGH). A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privileges and execute arbitrary commands when Service Mode is activated.
How severe is CVE-2022-40126?
CVE-2022-40126 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-40126?
Check the references section above for vendor advisories and patch information. Affected products include: Clash Project Clash.