Code Execution Vulnerability in AWS Client VPN for Windows by Amazon
CVE-2025-8069

7.3HIGH

Key Information:

Vendor

Aws

Vendor
CVE Published:
23 July 2025

What is CVE-2025-8069?

A vulnerability exists in the installation process of AWS Client VPN on Windows devices, where the setup references an insecure directory for the OpenSSL configuration. This allows non-admin users to inject arbitrary code, potentially leading to the execution of that code with elevated privileges if the installation is initiated by an admin user. This issue is specific to Windows and does not affect Linux or Mac systems. Users are advised to refrain from installing versions of AWS Client VPN earlier than 5.2.2 to protect against potential exploits.

Affected Version(s)

Client VPN Windows 4.1.0

Client VPN Windows 5.0.0 < 5.2.2

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-8069 : Code Execution Vulnerability in AWS Client VPN for Windows by Amazon