CVE-2020-24356: Local Privilege Escalation in cloudflared
Published Oct 2, 2020
·Updated
cloudflared versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems. When run on a Windows system, cloudflared searches for configuration files which could be abused by a malicious entity to execute commands as a privileged user. Version 2020.8.1 fixes this issue.
Affected Software
1 affected component
Cloudflare cloudflared<2020.8.1
Event History
Oct 2, 2020
CVE Published
via MITRE·02:16 PM
Data Sourced
via MITRE·02:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-24356.
2
What is the severity of CVE-2020-24356?
The severity of CVE-2020-24356 is high.
3
What is the affected software for CVE-2020-24356?
The affected software for CVE-2020-24356 is cloudflared versions prior to 2020.8.1.
4
How can the vulnerability CVE-2020-24356 be exploited?
The vulnerability CVE-2020-24356 can be exploited by a malicious entity to execute commands as a privileged user on Windows systems.
5
How do I fix CVE-2020-24356?
To fix CVE-2020-24356, update cloudflared to version 2020.8.1 or newer.