CVE-2023-1412 is an improper access control vulnerability in the Cloudflare WARP Client for Windows (<= 2022.12.582.0). An unprivileged user can exploit a flaw in the MSI installer's repair function, utilizing opportunistic locks and symbolic links, to achieve SYSTEM-level privileges. This high-severity vulnerability (CVSS 7.8) allows for arbitrary file deletion and content reading, leading to potential system file manipulation and privilege escalation. While not actively exploited or having public exploit code, users are advised to upgrade to version 2023.3.381.0 or later and remove older installers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2023.3.381.0CPE matchmatch criteria | cpe:2.3:a:cloudflare:warp:*:*:*:*:*:windows:*:* | ||
>= 0, <= 2022.5.309.0CPE match | cpe:2.3:a:cloudflare:warp:*:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.