Privilege Escalation Vulnerability in Amazon CloudWatch Agent for Windows
CVE-2022-23511
7.1HIGH
What is CVE-2022-23511?
A privilege escalation issue exists in the Amazon CloudWatch Agent for Windows, affecting versions up to and including v1.247354. When the Agent is repaired, a pop-up window with SYSTEM permissions may appear, allowing users with administrative access to execute a command prompt as NT AUTHORITY\SYSTEM. This vulnerability requires an attacker to have administrative access to the host and the ability to trigger the agent repair process, making it critical for users to upgrade to version 1.247355 to resolve the issue, as there are no workarounds available.
Affected Version(s)
amazon-cloudwatch-agent < 1.247355