First published: Fri Oct 02 2020(Updated: )
`cloudflared` versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems. When run on a Windows system, `cloudflared` searches for configuration files which could be abused by a malicious entity to execute commands as a privileged user. Version 2020.8.1 fixes this issue.
Credit: cna@cloudflare.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudflare Cloudflared | <2020.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-24356.
The severity of CVE-2020-24356 is high.
The affected software for CVE-2020-24356 is cloudflared versions prior to 2020.8.1.
The vulnerability CVE-2020-24356 can be exploited by a malicious entity to execute commands as a privileged user on Windows systems.
To fix CVE-2020-24356, update cloudflared to version 2020.8.1 or newer.