CVE-2020-24356
EUVD-2021-110302.10.2020, 15:15
`cloudflared` versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems. When run on a Windows system, `cloudflared` searches for configuration files which could be abused by a malicious entity to execute commands as a privileged user. Version 2020.8.1 fixes this issue.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cloudflare | cloudflared | 𝑥 < 2020.8.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration