CVE-2025-0651 – Cloudflare WARP Windows Privilege Escalation File Manipulation Vulnerability

The following table lists the changes that have been made to the
CVE-2025-0651 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jan. 22, 2025

    Action Type Old Value New Value
    Added Description Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation.

    User with a low system privileges  can create a set of symlinks inside the C:ProgramDataCloudflarewarp-diag-partials folder. After triggering the ‘Reset all settings” option the WARP service will delete the files that the symlink was pointing to. Given the WARP service operates with System privileges this might lead to deleting files owned by the System user.
    This issue affects WARP: before 2024.12.492.0.

    Added CVSS V4.0 AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:X/R:U/V:X/RE:L/U:Green
    Added CWE CWE-269
    Added Reference https://developers.cloudflare.com/warp-client/
Share the Post:

Related Posts