Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v9x5-mfpj-jr3h

Опубликовано: 07 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 7.8

Описание

Improper Link Resolution Before File Access in the AWS VPN Client for macOS versions 1.3.2- 5.2.0 allows a local user to execute code with elevated privileges. Insufficient validation checks on the log destination directory during log rotation could allow a non-administrator user to create a symlink from a client log file to a privileged location. On log rotation, this could lead to code execution with root privileges if the user made crafted API calls which injected arbitrary code into the log file. We recommend users upgrade to AWS VPN Client for macOS 5.2.1 or the latest version.

Improper Link Resolution Before File Access in the AWS VPN Client for macOS versions 1.3.2- 5.2.0 allows a local user to execute code with elevated privileges. Insufficient validation checks on the log destination directory during log rotation could allow a non-administrator user to create a symlink from a client log file to a privileged location. On log rotation, this could lead to code execution with root privileges if the user made crafted API calls which injected arbitrary code into the log file. We recommend users upgrade to AWS VPN Client for macOS 5.2.1 or the latest version.

EPSS

Процентиль: 12%
0.0004
Низкий

9.3 Critical

CVSS4

7.8 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.8
nvd
4 месяца назад

Improper Link Resolution Before File Access in the AWS VPN Client for macOS versions 1.3.2- 5.2.0 allows a local user to execute code with elevated privileges. Insufficient validation checks on the log destination directory during log rotation could allow a non-administrator user to create a symlink from a client log file to a privileged location. On log rotation, this could lead to code execution with root privileges if the user made crafted API calls which injected arbitrary code into the log file. We recommend users upgrade to AWS VPN Client for macOS 5.2.1 or the latest version.

CVSS3: 7.8
fstec
4 месяца назад

Уязвимость приложения безопасного туннелирования AWS VPN Client, связанная с неверным определением ссылки перед доступом к файлу, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 12%
0.0004
Низкий

9.3 Critical

CVSS4

7.8 High

CVSS3

Дефекты

CWE-59