PT-2023-14443 · Cloudflare · Warp Client
Cf
+2
·
Published
2023-01-11
·
Updated
2023-01-19
·
CVE-2022-4428
CVSS v3.1
8.9
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
WARP client (affected versions not specified)
Description
The support uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation, allowing for privilege escalation and launching an arbitrary executable on the local machine upon clicking on the "Send feedback" option. An attacker with access to the local file system could use a crafted XML config file pointing to a malicious file or set a local path to the executable using Cloudflare Zero Trust Dashboard (for Zero Trust enrolled clients).
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Warp Client