TOCTOU Race Condition in Amazon AWS VPN Client
CVE-2022-25165
7HIGH
What is CVE-2022-25165?
A vulnerability was identified in Amazon AWS VPN Client 2.0.0, where a TOCTOU (Time-of-check to Time-of-use) race condition exists during the validation process of VPN configuration files. This flaw enables low-level users to inject parameters that are not on the AWS VPN Client allow list into the configuration file before it's processed by the AWS VPN Client service, which runs with SYSTEM privileges. This can lead to dangerous arguments being utilized for log file destinations, allowing an arbitrary file write with limited control over its content. Exploiting this vulnerability may enable an attacker to escalate their privileges or create a denial of service.