CVE-2022-2147

Cloudflare Warp for Windows from version 2022.2.95.0 contained an unquoted service path which enables arbitrary code execution leading to privilege escalation. The fix was released in version 2022.3.186.0.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:cloudflare:warp:*:*:*:*:*:windows:*:*

History

01 Jul 2022, 13:22

Type Values Removed Values Added
References (CONFIRM) https://github.com/cloudflare/advisories/security/advisories/GHSA-m6w8-3pf9-p68r - (CONFIRM) https://github.com/cloudflare/advisories/security/advisories/GHSA-m6w8-3pf9-p68r - Release Notes, Third Party Advisory
CWE CWE-428
CPE cpe:2.3:a:cloudflare:warp:*:*:*:*:*:windows:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.6
v3 : 7.8

23 Jun 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-23 21:15

Updated : 2024-02-04 22:29


NVD link : CVE-2022-2147

Mitre link : CVE-2022-2147

CVE.ORG link : CVE-2022-2147


JSON object : View

Products Affected

cloudflare

  • warp
CWE
CWE-428

Unquoted Search Path or Element