Cloudflare WARP Client for Windows Privilege Escalation Vulnerability Allowing Arbitrary File Overwrite

Vulnerability

A vulnerability in the Cloudflare WARP client for Windows, in versions prior to 2022.5.309.0, allowed the creation of mount points from the ProgramData folder. This issue could be exploited during the installation of the WARP client to escalate privileges and overwrite files protected by the SYSTEM.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation and the ability to overwrite critical SYSTEM files.

Remediation

Users can upgrade to Cloudflare WARP client version 2022.5.309.0 or later to address this vulnerability.

Added: Mar 11, 2026, 6:51 PM
Updated: Mar 11, 2026, 6:51 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
10.0
exploitability
2.6
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.