CVE-2023-0652
Local Privilege Escalation in Cloudflare WARP Installer (Windows)Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WARP Client for Windows (<= 2022.12.582.0) allowed a malicious attacker to forge the destination of the hardlink and escalate privileges, overwriting SYSTEM protected files.
As Cloudflare WARP client for Windows (up to version 2022.5.309.0) allowed creation of mount points from its ProgramData folder, during installation of the WARP client, it was possible to escalate privileges and overwrite SYSTEM protected files.
We have discovered 180 live websites that are affected by CVE-2023-0652.
Contact us to get more info
Affected Software
| |
---|
Product | Warp |
Category | Web Servers |
Vulnerable Versions | - from 0 through 2022.5.309
|
Total Vulnerable Versions | 38 |
Vulnerable Domains | 180 live websites (100.00% of Warp install base) |
Common Weakness Enumeration
CWE-59 Improper Link Resolution Before File Access ('Link Following')
Distribution by Website Rank
The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-0652 and the relative popularity of websites