Remote Code Execution Vulnerability in Amazon AWS VPN Client
CVE-2022-25166

5MEDIUM

Key Information:

Vendor

Amazon

Vendor
CVE Published:
14 April 2022

What is CVE-2022-25166?

A vulnerability in the AWS VPN Client version 2.0.0 allows attackers to craft malicious OpenVPN configuration files. When users import these files, the VPN client references UNC paths for parameters like auth-user-pass, inadvertently triggering a file operation that exposes the user's Net-NTLMv2 hash to external servers. This can facilitate further exploits if a user inadvertently uses a compromised configuration file.

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.