Plaintext transmission of DNS requests in Windows 1.1.1.1 WARP client
CVE-2023-2754
What is CVE-2023-2754?
The Cloudflare WARP client for Windows has a vulnerability that affects its DNS query handling when deployed on IPv6-capable networks. While the client properly assigns loopback IPv4 addresses to DNS servers, it fails to do the same for IPv6, opting instead for Unique Local Addresses (ULAs). This misconfiguration can inadvertently expose DNS queries to potential attackers who are present on the same local network. Consequently, these malicious entities may gain access to sensitive query information from devices using the WARP client, undermining the intended security features of the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WARP Windows 0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
