CVE-2021-43638: Integer Overflow
Amazon Amazon WorkSpaces agent is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-43638.
What is the severity of CVE-2021-43638?
The severity of CVE-2021-43638 is high, with a severity value of 8.8.
Which software is affected by CVE-2021-43638?
Amazon WorkSpaces agent below v1.0.1.1537 is affected by CVE-2021-43638.
How can local attackers exploit CVE-2021-43638?
Local attackers can exploit CVE-2021-43638 to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packets.
Is there a fix available for CVE-2021-43638?
Yes, the fix for CVE-2021-43638 is to update the Amazon WorkSpaces agent to version 1.0.1.1537 or above.