Skip to content
CloudflareGHSA-hgwp-4vp4-qmm2

Local Privilege Escalation in cloudflared

MediumCVE-2020-24356 · Published Sep 16, 2020

In `cloudflared` versions < 2020.8.1 on Windows, if an administrator has started `cloudflared` and set it to read configuration files from a certain directory, an unprivileged user can exploit a misconfiguration in order to escalate privileges and execute system-level commands. The misconfiguration was due to the way that `cloudflared` reads its configuration file. One of the locations that `cloudflared` reads from (C:\etc\) is not a secure by default directory due to the fact that Windows does not enforce access controls on this directory without further controls applied. A malformed config.yaml file can be written by any user. Upon reading this config, `cloudflared` would output an error message to a log file defined in the malformed config. The user-controlled log file location could be set to a specific location that Windows will execute when any user logs in.

GitHub advisory

Affected versions

PackageAffectedFixed in
cloudflared
Product
< 2020.8.12020.8.1
Details and references

More Cloudflare advisories

All Cloudflare
Advisory
Resource exhaustion via memory leak in tokio-boring
Medium5.3Dec 5, 2023
WebSocket message can cause crash
MediumNov 21, 2023
Directory traversal vulnerability in Cloudflare Wrangler
Medium5.7Aug 3, 2023
Buffer under-read in workerd
Medium6.5May 12, 2023
Improper random reading in CIRCL
Medium5.3May 10, 2023
Local Privilege Escalation Vulnerability in cloudflared's Installer
High7.5Mar 21, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.