CVE-2022-2145
Summary
| CVE | CVE-2022-2145 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-28 18:15:00 UTC |
| Updated | 2022-07-08 13:37:00 UTC |
| Description | Cloudflare WARP client for Windows (up to v. 2022.5.309.0) allowed creation of mount points from its ProgramData folder. During installation of the WARP client, it was possible to escalate privileges and overwrite SYSTEM protected files. |
Risk And Classification
Problem Types: CWE-59
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cloudflare | Warp | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cloudflare WARP Client Arbitrary File Overwrite · Advisory · cloudflare/advisories · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Patrick Murphy (@hackandpwn)
There are currently no legacy QID mappings associated with this CVE.