`cloudflared` versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems. When run on a Windows system, `cloudflared` searches for configuration files which could be abused by a malicious entity to execute commands as a privileged user. Version 2020.8.1 fixes this issue.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1103 | `cloudflared` versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems. When run on a Windows system, `cloudflared` searches for configuration files which could be abused by a malicious entity to execute commands as a privileged user. Version 2020.8.1 fixes this issue. |
Github GHSA |
GHSA-hgwp-4vp4-qmm2 | Local Privilege Escalation in cloudflared |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: cloudflare
Published:
Updated: 2024-09-17T01:46:28.741Z
Reserved: 2020-08-14T00:00:00
Link: CVE-2020-24356
No data.
Status : Modified
Published: 2020-10-02T15:15:12.483
Modified: 2024-11-21T05:14:39.480
Link: CVE-2020-24356
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA