CVE-2020-35152
Privilege escalation through unquoted service binary path on Cloudflare WARP for Windows
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cloudflare WARP for Windows allows privilege escalation due to an unquoted service path. A malicious user or process running with non-administrative privileges can become an administrator by abusing the unquoted service path issue. Since version 1.2.2695.1, the vulnerability was fixed by adding quotes around the service's binary path. This issue affects Cloudflare WARP for Windows, versions prior to 1.2.2695.1.
Cloudflare WARP para Windows permite un escalada de privilegios debido a una ruta de servicio sin comillas. Un usuario o proceso malicioso que se ejecuta con privilegios no administrativos puede convertirse en administrador si abusa del problema de la ruta de servicio sin comillas. A partir la versión 1.2.2695.1, la vulnerabilidad se solucionó agregando comillas alrededor de la ruta binaria del servicio. Este problema afecta a Cloudflare WARP para Windows, versiones anteriores a 1.2.2695.1
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-12-11 CVE Reserved
- 2021-02-02 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-428: Unquoted Search Path or Element
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/cloudflare/advisories/security/advisories/GHSA-qc57-v5q8-f22h | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cloudflare Search vendor "Cloudflare" | Warp Search vendor "Cloudflare" for product "Warp" | < 1.2.2695.1 Search vendor "Cloudflare" for product "Warp" and version " < 1.2.2695.1" | windows |
Affected
|