CVE-2023-1862
CVSS 3.1 Score 7.3 of 10 (high)
Details
Summary
CVE-2023-1862 is a vulnerability affecting the Cloudflare WARP client for Windows, version up to v2023.3.381.0. This issue stems from an inadequate access control policy on an IPC Named Pipe, which enables a malicious actor to remotely access the warp-svc.exe binary. The exploitation of this vulnerability allows an attacker to trigger WARP connect and disconnect commands, obtain network diagnostics, and gain access to application configurations on the target device. However, it's important to note that this attack requires the target device to be reachable on port 445 and either allowing authentication with NULL sessions or having the attacker's credentials.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cloudflare Warp
Affected Vendors
- CloudFlare