First published: Mon Oct 30 2017(Updated: )
The Amazon Web Services (AWS) CloudFormation bootstrap tools package (aka aws-cfn-bootstrap) before 1.4-19.10 allows local users to execute arbitrary code with root privileges by leveraging the ability to create files in an unspecified directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Web Services CloudFormation | <1.4-19.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9450 has a high severity rating as it allows local users to execute arbitrary code with root privileges.
To fix CVE-2017-9450, update the AWS CloudFormation bootstrap tools package to version 1.4-19.10 or later.
CVE-2017-9450 affects local users of AWS CloudFormation bootstrap tools package versions prior to 1.4-19.10.
CVE-2017-9450 allows local users to perform arbitrary code execution, potentially leading to full system compromise.
No, CVE-2017-9450 is a local vulnerability requiring local user access to exploit.