Local Privilege Escalation in Cloudflare WARP Installer (Windows)
CVE-2023-0652
What is CVE-2023-0652?
The Cloudflare WARP Client for Windows has a vulnerability that arises from the creation of hardlinks during its installation process. Specifically, when the installer creates these hardlinks in the ProgramData folder, an attacker could manipulate the destination of the hardlink to escalate their privileges. This manipulation allows unauthorized access to overwrite files that are typically protected by the SYSTEM user, leading to significant security risks. Users are advised to update their installations to mitigate potential threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WARP Windows 0 <= 2022.5.309.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
