Skip to content
AWSGHSA-j8x2-2m5w-j939

Privilege Escalation Vector in CloudWatch Agent for Windows

High7.1CVE-2022-23511 · Published Dec 10, 2022 · updated Jan 4, 2023

### Impact A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows in versions up to and including v1.247354. When users trigger a repair of the Agent, a pop-up window opens with SYSTEM permissions. Users with administrative access to affected hosts may use this to create a new command prompt as NT AUTHORITY\SYSTEM. To trigger this issue, the third party must be able to access the affected host. They must also be able to install the tools required to trigger the issue. This issue does not affect the CloudWatch Agent for macOS or Linux. ### Patches We recommend that Agent users upgrade to the latest available version of the CloudWatch Agent to address this issue. ### Workarounds There is no recommended work around. Affected users must update the installed version of the CloudWatch Agent to address this issue. ### References https://github.com/aws/amazon-cloudwatch-agent/commit/6119858864c317ff26f41f576c169148d1250837 ### For more information If you have any questions or comments about this advisory, we ask that you contact AWS/Amazon Security via our [vulnerability reporting page](http://aws.amazon.com/security/vulnerability-reporting/) or directly ...

GitHub advisory

Affected versions

PackageAffectedFixed in
amazon-cloudwatch-agent
Go
< 1.2473551.247355
Details and references

### Impact A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows in versions up to and including v1.247354. When users trigger a repair of the Agent, a pop-up window opens with SYSTEM permissions. Users with administrative access to affected hosts may use this to create a new command prompt as NT AUTHORITY\SYSTEM. To trigger this issue, the third party must be able to access the affected host. They must also be able to install the tools required to trigger the issue. This issue does not affect the CloudWatch Agent for macOS or Linux. ### Patches We recommend that Agent users upgrade to the latest available version of the CloudWatch Agent to address this issue. ### Workarounds There is no recommended work around. Affected users must update the installed version of the CloudWatch Agent to address this issue. ### References https://github.com/aws/amazon-cloudwatch-agent/commit/6119858864c317ff26f41f576c169148d1250837 ### For more information If you have any questions or comments about this advisory, we ask that you contact AWS/Amazon Security via our [vulnerability reporting page](http://aws.amazon.com/security/vulnerability-reporting/) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-274

More AWS advisories

All AWS
Advisory
EKS overly permissive trust policies
Medium6.6Jun 19, 2023
Issue with parsing Certificate Common Name (CN) in s2n-tls
LowFeb 14, 2023
Issue with configuring session ticket names in s2n-tls
MediumSep 27, 2022
Server denial-of-service by using sslv2 message format in a HelloRetryRequest handshake
LowSep 27, 2022
Partial Path Traversal in aws-cpp-sdk-transfer
MediumAug 9, 2022
Partial Path Traversal in com.amazonaws:aws-java-sdk-s3
High7.9Jul 15, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.