First published: Thu Jun 23 2022(Updated: )
Cloudflare Warp for Windows from version 2022.2.95.0 contained an unquoted service path which enables arbitrary code execution leading to privilege escalation. The fix was released in version 2022.3.186.0.
Credit: cna@cloudflare.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudflare Warp | >=2022.2.95.0<2022.3.186.0 |
Upgrade WARP to the newest version (at least 2022.3.186.0)
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-2147.
The severity of CVE-2022-2147 is high.
The affected software is Cloudflare Warp for Windows version 2022.2.95.0 to 2022.3.186.0.
An attacker can exploit CVE-2022-2147 by running arbitrary code with elevated privileges.
To fix CVE-2022-2147, update Cloudflare Warp for Windows to version 2022.3.186.0 or later.