Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-0651

Опубликовано: 22 янв. 2025
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation.

User with a low system privileges  can create a set of symlinks inside the C:\ProgramData\Cloudflare\warp-diag-partials folder. After triggering the 'Reset all settings" option the WARP service will delete the files that the symlink was pointing to. Given the WARP service operates with System privileges this might lead to deleting files owned by the System user. This issue affects WARP: before 2024.12.492.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cloudflare:warp:*:*:*:*:*:windows:*:*
Версия до 2024.12.492.0 (исключая)

EPSS

Процентиль: 21%
0.00068
Низкий

7.1 High

CVSS3

Дефекты

CWE-269
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.1
github
около 1 года назад

Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation. User with a low system privileges  can create a set of symlinks inside the C:\ProgramData\Cloudflare\warp-diag-partials folder. After triggering the 'Reset all settings" option the WARP service will delete the files that the symlink was pointing to. Given the WARP service operates with System privileges this might lead to deleting files owned by the System user. This issue affects WARP: before 2024.12.492.0.

EPSS

Процентиль: 21%
0.00068
Низкий

7.1 High

CVSS3

Дефекты

CWE-269
NVD-CWE-noinfo