Privilege Escalation Vulnerability in Harmonix on AWS Framework by AWS
CVE-2025-14503
What is CVE-2025-14503?
The Harmonix on AWS framework contains a vulnerability due to an overly permissive IAM trust policy that permits authenticated users to escalate their privileges through role assumption. Specifically, the sample code for the EKS environment provisioning role trusts the account root principal, which can be exploited by any account principal possessing sts:AssumeRole permissions to assume the role with administrative privileges. To mitigate this risk, it is advisable for users to upgrade to Harmonix on AWS version 0.4.2 or later, especially if they are currently utilizing versions 0.3.0 through 0.4.1.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Harmonix on AWS 0.3.0 < 0.4.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
