support_uri validation missing in WARP client for Windows
CVE-2022-4428
What is CVE-2022-4428?
The WARP client suffers from a vulnerability due to improper validation of the support_uri parameter in its local settings file (mdm.xml). This flaw enables an attacker with access to the local file system to manipulate the XML configuration, allowing them to point to a malicious executable. When a user clicks the 'Send feedback' option, this can lead to the execution of arbitrary code on the local machine. The vulnerability can be exploited via crafted XML files, exploiting the integration with the Cloudflare Zero Trust Dashboard.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WARP Windows 0 <= 2022.10.106.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
