Privilege Escalation Vulnerability in Amazon CloudWatch Agent for Windows
CVE-2022-23511
What is CVE-2022-23511?
A privilege escalation issue exists in the Amazon CloudWatch Agent for Windows, affecting versions up to and including v1.247354. When the Agent is repaired, a pop-up window with SYSTEM permissions may appear, allowing users with administrative access to execute a command prompt as NT AUTHORITY\SYSTEM. This vulnerability requires an attacker to have administrative access to the host and the ability to trigger the agent repair process, making it critical for users to upgrade to version 1.247355 to resolve the issue, as there are no workarounds available.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
amazon-cloudwatch-agent < 1.247355
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
