← Back

CVE-2022-2145

nvd nist
Published: Jun 28, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Cloudflare WARP client for Windows (up to v. 2022.5.309.0) allowed creation of mount points from its ProgramData folder. During installation of the WARP client, it was possible to escalate privileges and overwrite SYSTEM protected files.

Affected (1)

Products: Cloudflare: Warp
1 product
Warp
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2022.5.309.0

References (2)

Source: cna@cloudflare.com
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory

Timeline

No history available yet.