PT-2021-23898 · Amazon · Amazon Workspaces Agent
Kasif Dekel
·
Published
2021-12-07
·
Updated
2021-12-09
·
CVE-2021-43638
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Amazon WorkSpaces agent versions prior to 1.0.1.1537
Description:
The issue is related to an Integer Overflow in the Amazon WorkSpaces agent. It affects the IOCTL Handler 0x22001B, allowing local attackers to execute arbitrary code in kernel mode or cause a denial of service, resulting in memory corruption and OS crash, via specially crafted I/O Request Packets.
Recommendations:
For versions prior to 1.0.1.1537, update to version 1.0.1.1537 or later to resolve the issue. As a temporary workaround, consider restricting access to the IOCTL Handler 0x22001B to minimize the risk of exploitation.
Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amazon Workspaces Agent