CVE-2022-40126

HIGH

Clash for Windows <0.19.9 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privileges and execute arbitrary commands when Service Mode is activated.

Exploits (1)

nomisec WORKING POC 4 stars
by LovelyWei · poc
https://github.com/LovelyWei/CVE-2022-40126

References (1)

Core 1
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/Fndroid/clash_for_windows_pkg/issues/3405

Scores

CVSS v3 7.8
EPSS 0.0011
EPSS Percentile 28.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-552
Status published
Products (1)
clash_project/clash 0.19.9
Published Sep 29, 2022
Tracked Since Feb 18, 2026