CVE-2023-0652 is a privilege escalation vulnerability affecting Cloudflare WARP Client for Windows versions up to 2022.12.582.0. The flaw stems from the installer's creation of hardlinks or mount points in the ProgramData folder, which an attacker could manipulate to overwrite SYSTEM-protected files. With a CVSS score of 7.8 (High), this vulnerability allows a local attacker with low privileges to achieve full confidentiality, integrity, and availability impact without user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2023.3.381.0CPE matchmatch criteria | cpe:2.3:a:cloudflare:warp:*:*:*:*:*:windows:*:* | ||
>= 0, <= 2022.5.309.0CPE match | cpe:2.3:a:cloudflare:warp:*:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.