CVE-2022-2145: Cloudlfare WARP Arbitrary File Overwrite
Cloudflare WARP client for Windows (up to v. 2022.5.309.0) allowed creation of mount points from its ProgramData folder. During installation of the WARP client, it was possible to escalate privileges and overwrite SYSTEM protected files.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this Cloudflare WARP client vulnerability?
The vulnerability ID for this Cloudflare WARP client vulnerability is CVE-2022-2145.
What is the severity of CVE-2022-2145?
The severity of CVE-2022-2145 is high with a CVSS score of 7.8.
Which software versions are affected by CVE-2022-2145?
Cloudflare WARP client for Windows up to v. 2022.5.309.0 is affected by CVE-2022-2145.
How can the privilege escalation and overwriting of SYSTEM protected files be performed in this vulnerability?
The privilege escalation and overwriting of SYSTEM protected files can be performed during the installation of the WARP client by creating mount points from its ProgramData folder.
Is there a fix available for CVE-2022-2145?
Yes, Cloudflare has released a fix for CVE-2022-2145. It is recommended to update to the latest version of the Cloudflare WARP client for Windows.