VYPR
Unrated severityNVD Advisory· Published Apr 6, 2023· Updated Feb 10, 2025

Local Privilege Escalation in Cloudflare WARP Installer (Windows)

CVE-2023-0652

Description

Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WARP Client for Windows (<= 2022.12.582.0) allowed a malicious attacker to forge the destination of the hardlink and escalate privileges, overwriting SYSTEM protected files. As Cloudflare WARP client for Windows (up to version 2022.5.309.0) allowed creation of mount points from its ProgramData folder, during installation of the WARP client, it was possible to escalate privileges and overwrite SYSTEM protected files.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Local privilege escalation in WARP Client installer via hardlink manipulation allows SYSTEM file overwrite.

Vulnerability

A privilege escalation vulnerability exists in the installer (MSI) of Cloudflare WARP Client for Windows versions up to and including 2022.12.582.0. During the repair process, the installer creates a hardlink in the ProgramData folder. An attacker can forge the destination of this hardlink, or (in versions up to 2022.5.309.0) create mount points from the same folder, to redirect the installer's file operations to arbitrary locations protected by SYSTEM [2].

Exploitation

To exploit this vulnerability, an attacker must already have local access to the Windows system. No additional authentication or user interaction is required beyond initiating the installer repair process. The attacker creates a hardlink or mount point in the ProgramData folder that points to a SYSTEM-protected file. When the installer repair runs, it follows the hardlink and overwrites the targeted system file with content controlled by the attacker [2].

Impact

A successful attack allows the attacker to overwrite arbitrary SYSTEM-protected files, leading to escalation of privileges from a local non-administrator context to SYSTEM. The attacker can replace critical system binaries or configuration files, potentially achieving persistent code execution at the highest privilege level [2].

Mitigation

Cloudflare released a fixed installer in WARP Client version 2023.3.381.0. Users should upgrade to this version or later and delete any older installer executables from their systems. The WARP Client itself is not vulnerable, only the installer binary [2].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.