CVE-2022-2145

MEDIUM

Cloudflare WARP <2022.5.309.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Cloudflare WARP client for Windows (up to v. 2022.5.309.0) allowed creation of mount points from its ProgramData folder. During installation of the WARP client, it was possible to escalate privileges and overwrite SYSTEM protected files.

References (1)

Core 1
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/cloudflare/advisories/security/advisories/GHSA-6fpc-qxmr-6wrq

Scores

CVSS v3 5.8
EPSS 0.0028
EPSS Percentile 19.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:H

Details

CWE
CWE-20 CWE-59
Status published
Products (1)
cloudflare/warp < 2022.5.309.0
Published Jun 28, 2022
Tracked Since Feb 18, 2026