Cloudflare WARP
cpe:2.3:a:cloudflare:warp:*:*:*:*:windows:*:*
- < 2023.3.381.0
A vulnerability in the Cloudflare WARP client for Windows, in versions prior to 2023.3.381.0, allowed remote access to the warp-svc.exe binary. This issue arose from inadequate access control on an IPC Named Pipe, enabling attackers to send WARP connect and disconnect commands, as well as retrieve network diagnostics and application configuration from the victim's device. Exploitation required the target device to be accessible on port 445, to permit NULL session authentication, or to have knowledge of the target's credentials.
Successful exploitation allowed remote access to the WARP service, enabling the execution of connect and disconnect commands and the retrieval of network diagnostics and application configuration from the target device.
Users can update to Cloudflare WARP client version 2023.3.381.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.