Vulnerability Details CVE-2022-2147
Cloudflare Warp for Windows from version 2022.2.95.0 contained an unquoted service path which enables arbitrary code execution leading to privilege escalation. The fix was released in version 2022.3.186.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.6%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.6
Products affected by CVE-2022-2147
-
cpe:2.3:a:cloudflare:warp:2022.2.247.0
-
cpe:2.3:a:cloudflare:warp:2022.2.95.0
-
cpe:2.3:a:cloudflare:warp:2022.3.63.0