1 results (0.006 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml). • https://github.com/Fndroid/clash_for_windows_pkg https://github.com/Fndroid/clash_for_windows_pkg/issues/3891 • CWE-732: Incorrect Permission Assignment for Critical Resource •