Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pmfv-5ppm-9fqc

Опубликовано: 23 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.3
CVSS3: 7.8

Описание

During the AWS Client VPN client installation on Windows devices, the install process references the C:\usr\local\windows-x86_64-openssl-localbuild\ssl directory location to fetch the OpenSSL configuration file. As a result, a non-admin user could place arbitrary code in the configuration file. If an admin user starts the AWS Client VPN client installation process, that code could be executed with root-level privileges. This issue does not affect Linux or Mac devices.

We recommend users discontinue any new installations of AWS Client VPN on Windows prior to version 5.2.2.

During the AWS Client VPN client installation on Windows devices, the install process references the C:\usr\local\windows-x86_64-openssl-localbuild\ssl directory location to fetch the OpenSSL configuration file. As a result, a non-admin user could place arbitrary code in the configuration file. If an admin user starts the AWS Client VPN client installation process, that code could be executed with root-level privileges. This issue does not affect Linux or Mac devices.

We recommend users discontinue any new installations of AWS Client VPN on Windows prior to version 5.2.2.

EPSS

Процентиль: 2%
0.00015
Низкий

7.3 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 7.8
nvd
около 2 месяцев назад

During the AWS Client VPN client installation on Windows devices, the install process references the C:\usr\local\windows-x86_64-openssl-localbuild\ssl directory location to fetch the OpenSSL configuration file. As a result, a non-admin user could place arbitrary code in the configuration file. If an admin user starts the AWS Client VPN client installation process, that code could be executed with root-level privileges. This issue does not affect Linux or Mac devices. We recommend users discontinue any new installations of AWS Client VPN on Windows prior to version 5.2.2.

EPSS

Процентиль: 2%
0.00015
Низкий

7.3 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-276