PT-2023-16965 · Cloudflare · Cloudflare Warp Client

Ncabetecf

·

Publicado

2023-04-05

·

Atualizado

2023-04-12

·

CVE-2023-1412

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cloudflare WARP Client for Windows versions <= 2022.12.582.0
Description An unprivileged user can exploit an Improper Access Control issue to perform privileged operations with SYSTEM context by using a combination of opportunistic locks and symbolic links. The vulnerability lies in the repair function of the MSI-Installer placed under C:WindowsInstaller after installing the Cloudflare WARP Client. This can lead to attacks including the manipulation of system files and privilege escalation, allowing an attacker to delete arbitrary files and read arbitrary file content.
Recommendations For versions <= 2022.12.582.0, upgrade to version 2023.3.381.0 or later and delete any older installers present in the system to address the vulnerability. As a temporary workaround, consider restricting access to the MSI-Installer under C:WindowsInstaller to minimize the risk of exploitation.

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-1412
GHSA-HGXH-48M3-3GQ7

Produtos afetados

Cloudflare Warp Client