Remote Code Execution Vulnerability in Amazon AWS VPN Client
CVE-2022-25166
5MEDIUM
What is CVE-2022-25166?
A vulnerability in the AWS VPN Client version 2.0.0 allows attackers to craft malicious OpenVPN configuration files. When users import these files, the VPN client references UNC paths for parameters like auth-user-pass, inadvertently triggering a file operation that exposes the user's Net-NTLMv2 hash to external servers. This can facilitate further exploits if a user inadvertently uses a compromised configuration file.
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved