Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9g4q-mq35-ffg3

Опубликовано: 22 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.1
CVSS3: 7.1

Описание

Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation.

User with a low system privileges  can create a set of symlinks inside the C:\ProgramData\Cloudflare\warp-diag-partials folder. After triggering the 'Reset all settings" option the WARP service will delete the files that the symlink was pointing to. Given the WARP service operates with System privileges this might lead to deleting files owned by the System user. This issue affects WARP: before 2024.12.492.0.

Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation.

User with a low system privileges  can create a set of symlinks inside the C:\ProgramData\Cloudflare\warp-diag-partials folder. After triggering the 'Reset all settings" option the WARP service will delete the files that the symlink was pointing to. Given the WARP service operates with System privileges this might lead to deleting files owned by the System user. This issue affects WARP: before 2024.12.492.0.

EPSS

Процентиль: 21%
0.00068
Низкий

6.1 Medium

CVSS4

7.1 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.1
nvd
около 1 года назад

Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation. User with a low system privileges  can create a set of symlinks inside the C:\ProgramData\Cloudflare\warp-diag-partials folder. After triggering the 'Reset all settings" option the WARP service will delete the files that the symlink was pointing to. Given the WARP service operates with System privileges this might lead to deleting files owned by the System user. This issue affects WARP: before 2024.12.492.0.

EPSS

Процентиль: 21%
0.00068
Низкий

6.1 Medium

CVSS4

7.1 High

CVSS3

Дефекты

CWE-269