Code Execution Vulnerability in AWS Client VPN for Windows by Amazon
CVE-2025-8069
What is CVE-2025-8069?
A vulnerability exists in the installation process of AWS Client VPN on Windows devices, where the setup references an insecure directory for the OpenSSL configuration. This allows non-admin users to inject arbitrary code, potentially leading to the execution of that code with elevated privileges if the installation is initiated by an admin user. This issue is specific to Windows and does not affect Linux or Mac systems. Users are advised to refrain from installing versions of AWS Client VPN earlier than 5.2.2 to protect against potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Client VPN Windows 4.1.0
Client VPN Windows 5.0.0 < 5.2.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
