Elevation of Privilege Issue in Amazon EMR by AWS
CVE-2025-8904

9CRITICAL

Key Information:

Vendor

Amazon

Status
Vendor
CVE Published:
13 August 2025

What is CVE-2025-8904?

A vulnerability in Amazon EMR's Secret Agent allows the creation of an insecure keytab file containing Kerberos credentials, stored in the /tmp/ directory. This poses a risk as users with access to this directory could potentially decrypt the stored keys, leading to unauthorized privilege escalation if they possess an additional account. It is crucial for users to upgrade to Amazon EMR version 7.5 or higher. For those operating versions between 6.10 and 7.4, it is recommended to utilize the bootstrap script and RPM files provided in the security fix.

Affected Version(s)

EMR 6.10 < 7.4

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
The Cyber Security Vulnerability Database.