CVE-2022-2147: Unquoted Service Path in Cloudflare WARP for Windows
Published Jun 23, 2022
·Updated
Cloudflare Warp for Windows from version 2022.2.95.0 contained an unquoted service path which enables arbitrary code execution leading to privilege escalation. The fix was released in version 2022.3.186.0.
Affected Software
1 affected component
Cloudflare Warp Windows>=2022.2.95.0<2022.3.186.0
Remediation
Information
Upgrade WARP to the newest version (at least 2022.3.186.0)
Event History
Jun 23, 2022
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this Cloudflare Warp for Windows vulnerability?
The vulnerability ID is CVE-2022-2147.
2
What is the severity of CVE-2022-2147?
The severity of CVE-2022-2147 is high.
3
What is the affected software for CVE-2022-2147?
The affected software is Cloudflare Warp for Windows version 2022.2.95.0 to 2022.3.186.0.
4
How can an attacker exploit CVE-2022-2147?
An attacker can exploit CVE-2022-2147 by running arbitrary code with elevated privileges.
5
How can I fix CVE-2022-2147?
To fix CVE-2022-2147, update Cloudflare Warp for Windows to version 2022.3.186.0 or later.