PT-2022-3576 · Amazon+1 · Amazon-Ssm-Agent+1

Matthias Gerstner

·

Published

2022-04-20

·

Updated

2024-06-15

·

CVE-2022-29527

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions amazon-ssm-agent versions prior to 3.1.1208.0
Description The issue is related to incorrect default permissions in the amazon-ssm-agent software. Exploitation of this issue can allow an attacker to create a file with arbitrary extension and elevate privileges to root. This occurs due to the creation of a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate privileges to root in certain situations involving a race condition.
Recommendations For versions prior to 3.1.1208.0, update to version 3.1.1208.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the sudoers file to prevent local attackers from injecting Sudo rules.

Exploit

Fix

Incorrect Permission

Race Condition

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04360
CVE-2022-29527
OPENSUSE-SU-2022_1510-1
OPENSUSE-SU-2024:12012-1
SUSE-SU-2022:1510-1
SUSE-SU-2022:3654-1
SUSE-SU-2022_1510-1
SUSE-SU-2022_3654-1

Affected Products

Suse
Amazon-Ssm-Agent