Local Privilege Escalation in Cloudflare WARP Installer (Windows)
CVE-2023-0652
7HIGH
What is CVE-2023-0652?
The Cloudflare WARP Client for Windows has a vulnerability that arises from the creation of hardlinks during its installation process. Specifically, when the installer creates these hardlinks in the ProgramData folder, an attacker could manipulate the destination of the hardlink to escalate their privileges. This manipulation allows unauthorized access to overwrite files that are typically protected by the SYSTEM user, leading to significant security risks. Users are advised to update their installations to mitigate potential threats.
Affected Version(s)
WARP Windows 0 <= 2022.5.309.0