Privilege Escalation Vulnerability in Amazon CloudWatch Agent for Windows
CVE-2022-23511

7.1HIGH

Key Information:

Vendor

Aws

Vendor
CVE Published:
12 December 2022

What is CVE-2022-23511?

A privilege escalation issue exists in the Amazon CloudWatch Agent for Windows, affecting versions up to and including v1.247354. When the Agent is repaired, a pop-up window with SYSTEM permissions may appear, allowing users with administrative access to execute a command prompt as NT AUTHORITY\SYSTEM. This vulnerability requires an attacker to have administrative access to the host and the ability to trigger the agent repair process, making it critical for users to upgrade to version 1.247355 to resolve the issue, as there are no workarounds available.

Affected Version(s)

amazon-cloudwatch-agent < 1.247355

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-23511 : Privilege Escalation Vulnerability in Amazon CloudWatch Agent for Windows