CVE-2023-0652
Estado: ModificadaAlta (7.8)—
Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WARP Client for Windows (<= 2022.12.582.0) allowed a malicious attacker to forge the destination of the hardlink and escalate privileges, overwriting SYSTEM protected files. As Cloudflare WARP client for Windows (up to version 2022.5.309.0) allowed creation of mount points from its ProgramData folder, during installation of the WARP client, it was possible to escalate privileges and overwrite SYSTEM protected files.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.29%
- Percentil entre todas las CVEs puntuadas: 20
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-59
- CWE-59
Referencias
- https://developers.cloudflare.com/warp-client/get-started/windows/
- https://github.com/cloudflare/advisories/security/advisories/GHSA-xmhj-9p83-xvw9
- https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-windows-1/distribution_groups/release
- https://developers.cloudflare.com/warp-client/get-started/windows/
- https://github.com/cloudflare/advisories/security/advisories/GHSA-xmhj-9p83-xvw9
- https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-windows-1/distribution_groups/release
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-0652",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-0652",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-02-10T20:21:04.296425Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cna@cloudflare.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "cna@cloudflare.com",
"affectedData": [
{
"vendor": "Cloudflare",
"modules": [
"MSI"
],
"product": "WARP",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "2023.3.381.0",
"status": "unaffected"
}
],
"version": "0",
"versionType": "N/A",
"lessThanOrEqual": "2022.5.309.0"
}
],
"platforms": [
"Windows"
],
"packageName": "WARP Installer",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-04-06T10:15:07.167",
"references": [
{
"url": "https://developers.cloudflare.com/warp-client/get-started/windows/",
"tags": [
"Product"
],
"source": "cna@cloudflare.com"
},
{
"url": "https://github.com/cloudflare/advisories/security/advisories/GHSA-xmhj-9p83-xvw9",
"tags": [
"Vendor Advisory"
],
"source": "cna@cloudflare.com"
},
{
"url": "https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-windows-1/distribution_groups/release",
"tags": [
"Release Notes"
],
"source": "cna@cloudflare.com"
},
{
"url": "https://developers.cloudflare.com/warp-client/get-started/windows/",
"tags": [
"Product"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/cloudflare/advisories/security/advisories/GHSA-xmhj-9p83-xvw9",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-windows-1/distribution_groups/release",
"tags": [
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cna@cloudflare.com",
"description": [
{
"lang": "en",
"value": "CWE-59"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-59"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WARP Client for Windows (<= 2022.12.582.0) allowed a malicious attacker to forge the destination of the hardlink and escalate privileges, overwriting SYSTEM protected files.\nAs Cloudflare WARP client for Windows (up to version 2022.5.309.0) allowed creation of mount points from its ProgramData folder, during installation of the WARP client, it was possible to escalate privileges and overwrite SYSTEM protected files.\n\n\n"
}
],
"lastModified": "2026-06-17T05:26:01.030",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cloudflare:warp:*:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "B8FB60C0-986F-4205-9EE1-05C745FEF2AB",
"versionEndExcluding": "2023.3.381.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cna@cloudflare.com"
}