Integer Overflow Vulnerability in Amazon WorkSpaces Agent
CVE-2021-43638
8.8HIGH
What is CVE-2021-43638?
The Amazon WorkSpaces agent below version 1.0.1.1537 is susceptible to an integer overflow vulnerability in the IOCTL Handler 0x22001B. This flaw may enable local attackers to craft specific I/O Request Packets that could lead to arbitrary code execution in kernel mode, potentially resulting in memory corruption and crashing the operating system.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved