CVE-2023-0652


Local Privilege Escalation in Cloudflare WARP Installer (Windows)

Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WARP Client for Windows (<= 2022.12.582.0) allowed a malicious attacker to forge the destination of the hardlink and escalate privileges, overwriting SYSTEM protected files. As Cloudflare WARP client for Windows (up to version 2022.5.309.0) allowed creation of mount points from its ProgramData folder, during installation of the WARP client, it was possible to escalate privileges and overwrite SYSTEM protected files.



We have discovered 180 live websites that are affected by CVE-2023-0652.

Contact us to get more info




Affected Software

Product  Warp
Category Web Servers
Vulnerable Versions
  • from 0 through 2022.5.309
Total Vulnerable Versions38
Vulnerable Domains180 live websites (100.00% of Warp install base)


Common Weakness Enumeration


CWE-59 Improper Link Resolution Before File Access ('Link Following')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-0652 and the relative popularity of websites


Details

  • Published - Apr 6, 2023
  • Updated - Apr 6, 2023

Credits

  • Jan-Luca Gruber (reporter)





Countries

United States79 websites



Germany50 websites
France11 websites
GB6 websites
Singapore5 websites
Sweden4 websites
Australia3 websites
2 websites
Canada2 websites
Switzerland2 websites

TLDs

.com67 websites
.de27 websites
.net18 websites
.org14 websites
.io9 websites
.se4 websites
.fr4 websites
.ch2 websites
.co.uk2 websites
.info2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-0652 through included software libraries and plugins.



References


Websites affected by CVE-2023-0652

Top websites that are affected by CVE-2023-0652. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
*********.coop United States***,***
*.****.com United States***,***
***.**********.com United States***,***
**********************.org GB***,***
**************.se Sweden*,***,***
***.*************.com Germany*,***,***
***.***********.com United States*,***,***
*********.org United States*,***,***
*******.de Germany*,***,***
****.*********.io France*,***,***
See full domain list