{"api_version":"1","generated_at":"2026-07-23T18:57:11+00:00","cve":"CVE-2022-2145","urls":{"html":"https://cve.report/CVE-2022-2145","api":"https://cve.report/api/cve/CVE-2022-2145.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-2145","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-2145"},"summary":{"title":"CVE-2022-2145","description":"Cloudflare WARP client for Windows (up to v. 2022.5.309.0) allowed creation of mount points from its ProgramData folder. During installation of the WARP client, it was possible to escalate privileges and overwrite SYSTEM protected files.","state":"PUBLIC","assigner":"cna@cloudflare.com","published_at":"2022-06-28 18:15:00","updated_at":"2022-07-08 13:37:00"},"problem_types":["CWE-59"],"metrics":[],"references":[{"url":"https://github.com/cloudflare/advisories/security/advisories/GHSA-6fpc-qxmr-6wrq","name":"https://github.com/cloudflare/advisories/security/advisories/GHSA-6fpc-qxmr-6wrq","refsource":"MISC","tags":[],"title":"Cloudflare WARP Client Arbitrary File Overwrite  · Advisory · cloudflare/advisories · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-2145","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-2145","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Patrick Murphy (@hackandpwn)","lang":""}],"nvd_cpes":[{"cve_year":"2022","cve_id":"2145","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cloudflare","cpe5":"warp","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cna@cloudflare.com","ID":"CVE-2022-2145","STATE":"PUBLIC","TITLE":"Cloudlfare WARP Arbitrary File Overwrite "},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"WARP","version":{"version_data":[{"platform":"Windows","version_affected":"<","version_value":"2022.5.309.0"}]}}]},"vendor_name":"Cloudflare"}]}},"credit":[{"lang":"eng","value":"Patrick Murphy (@hackandpwn)"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cloudflare WARP client for Windows (up to v. 2022.5.309.0) allowed creation of mount points from its ProgramData folder. During installation of the WARP client, it was possible to escalate privileges and overwrite SYSTEM protected files."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":5.8,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-20 Improper Input Validation"}]},{"description":[{"lang":"eng","value":"CWE-59 Improper Link Resolution Before File Access ('Link Following')"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://github.com/cloudflare/advisories/security/advisories/GHSA-6fpc-qxmr-6wrq","name":"https://github.com/cloudflare/advisories/security/advisories/GHSA-6fpc-qxmr-6wrq"}]},"solution":[{"lang":"eng","value":"Upgrade WARP client for Windows to the newest version (at least 2022.5.309.0.)"}],"source":{"advisory":"GHSA-6fpc-qxmr-6wrq","discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2022-06-28 18:15:00","lastModifiedDate":"2022-07-08 13:37:00","problem_types":["CWE-59"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.2},"severity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:cloudflare:warp:*:*:*:*:*:windows:*:*","versionEndExcluding":"2022.5.309.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}