CVE-2023-24205
- Reference to the description:
- Description:
- Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml).
- Last updated date:
- 03/03/2023
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 03/03/2023
- Reference url to background
https://github.com/Fndroid/clash_for_windows_pkg/issues/3891