1 results (0.010 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 1

23 Feb 2023 — Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml). • https://github.com/Fndroid/clash_for_windows_pkg • CWE-732: Incorrect Permission Assignment for Critical Resource •