PT-2021-21953 · Amazon · Amazon Workspaces

David Yesland

·

Published

2021-09-21

·

Updated

2021-10-01

·

CVE-2021-38112

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Amazon AWS WorkSpaces client versions 3.0.10 through 3.1.8
Description: The issue is related to argument injection in the workspaces:// URI handler, which can lead to remote code execution due to the Chromium Embedded Framework (CEF) --gpu-launcher argument.
Recommendations: For Amazon AWS WorkSpaces client versions 3.0.10 through 3.1.8, update to version 3.1.9 to resolve the issue. As a temporary workaround, consider restricting access to the workspaces:// URI handler until the update is applied.

Exploit

Fix

RCE

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-38112

Affected Products

Amazon Workspaces