First published: Tue Dec 07 2021(Updated: )
Amazon WorkSpaces agent is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon WorkSpaces | <1.0.1.1537 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43637 is a vulnerability in the Amazon WorkSpaces agent below v1.0.1.1537 that allows local attackers to execute arbitrary code in kernel mode or cause a denial of service.
CVE-2021-43637 affects the Amazon WorkSpaces agent, potentially allowing local attackers to execute arbitrary code in kernel mode or cause a denial of service.
CVE-2021-43637 has a severity rating of 8.8 (high).
To fix CVE-2021-43637, you should update the Amazon WorkSpaces agent to version 1.0.1.1537 or higher.
You can find more information about CVE-2021-43637 at the following reference: https://www.sentinelone.com/labs/usb-over-ethernet-multiple-privilege-escalation-vulnerabilities-in-aws-and-other-major-cloud-services/