Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation.
User with a low system privileges  can create a set of symlinks inside the C:\ProgramData\Cloudflare\warp-diag-partials folder. After triggering the 'Reset all settings" option the WARP service will delete the files that the symlink was pointing to. Given the WARP service operates with System privileges this might lead to deleting files owned by the System user.
This issue affects WARP: before 2024.12.492.0.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://developers.cloudflare.com/warp-client/ |     | 
History
                    Thu, 31 Jul 2025 20:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:cloudflare:warp:*:*:*:*:*:windows:*:* | |
| Metrics | cvssV3_1 
 | 
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Wed, 22 Jan 2025 17:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation. User with a low system privileges can create a set of symlinks inside the C:\ProgramData\Cloudflare\warp-diag-partials folder. After triggering the 'Reset all settings" option the WARP service will delete the files that the symlink was pointing to. Given the WARP service operates with System privileges this might lead to deleting files owned by the System user. This issue affects WARP: before 2024.12.492.0. | |
| Title | File symlink abuse might lead to deleting files belonging to SYSTEM user | |
| Weaknesses | CWE-269 | |
| References |  | |
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: cloudflare
Published: 2025-01-22T17:34:16.705Z
Updated: 2025-02-12T20:41:23.901Z
Reserved: 2025-01-22T15:57:16.758Z
Link: CVE-2025-0651
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-02-12T20:33:48.302Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-01-22T18:15:20.363
Modified: 2025-07-31T19:47:25.433
Link: CVE-2025-0651
 Redhat
                        Redhat
                    No data.