Buffer Overflow Vulnerability in Amazon AWS Client VPN on macOS
CVE-2024-30165
7.1HIGH
What is CVE-2024-30165?
The buffer overflow vulnerability in Amazon AWS Client VPN versions prior to 3.9.1 on macOS could permit a local actor to execute arbitrary commands with elevated permissions. This vulnerability poses a significant risk as it allows unauthorized users to exploit the flaw to potentially gain control over the system. Immediate updates to the latest version are recommended to mitigate the risk.
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published