Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-35152

Опубликовано: 03 фев. 2021
Источник: nvd
CVSS3: 4.5
CVSS3: 7.8
CVSS2: 4.6
EPSS Низкий

Описание

Cloudflare WARP for Windows allows privilege escalation due to an unquoted service path. A malicious user or process running with non-administrative privileges can become an administrator by abusing the unquoted service path issue. Since version 1.2.2695.1, the vulnerability was fixed by adding quotes around the service's binary path. This issue affects Cloudflare WARP for Windows, versions prior to 1.2.2695.1.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cloudflare:warp:*:*:*:*:*:windows:*:*
Версия до 1.2.2695.1 (исключая)

EPSS

Процентиль: 17%
0.00054
Низкий

4.5 Medium

CVSS3

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-428
CWE-428

EPSS

Процентиль: 17%
0.00054
Низкий

4.5 Medium

CVSS3

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-428
CWE-428