VYPR
Unrated severityNVD Advisory· Published Jan 11, 2023· Updated Apr 9, 2025

support_uri validation missing in WARP client for Windows

CVE-2022-4428

Description

support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privilege escalation and launching an arbitrary executable on the local machine upon clicking on the "Send feedback" option. An attacker with access to the local file system could use a crafted XML config file pointing to a malicious file or set a local path to the executable using Cloudflare Zero Trust Dashboard (for Zero Trust enrolled clients).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cloudflare WARP client for Windows lacks validation of the 'support_uri' in mdm.xml, allowing privilege escalation via arbitrary executable execution.

Vulnerability

The CVE-2022-4428 vulnerability resides in the Cloudflare WARP client for Windows, where the support_uri parameter in the mdm.xml local settings file is not properly validated. This allows an attacker with local file system access to craft a malicious XML configuration file pointing to an arbitrary executable. The issue affects versions prior to 2022.442.0 (the fix was released in version >=2022.476.0) [1].

Exploitation

An attacker needs write access to the local file system to modify or replace the mdm.xml file. Alternatively, for Zero Trust enrolled clients, the attacker could set a local path to the executable via the Cloudflare Zero Trust Dashboard. The exploit triggers when a user clicks the "Send feedback" option in the WARP client, which then launches the attacker-specified executable [1].

Impact

Successful exploitation results in privilege escalation and the ability to launch an arbitrary executable on the local machine. This could lead to complete compromise of the affected system, depending on the malicious executable launched [1].

Mitigation

The vendor released a fix in Cloudflare WARP for Windows version >=2022.476.0. Users should upgrade to the latest version immediately. No workarounds are mentioned in the available reference [1]. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of publication.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.