First published: Tue Dec 07 2021(Updated: )
Amazon Amazon WorkSpaces agent is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon WorkSpaces | <1.0.1.1537 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-43638.
The severity of CVE-2021-43638 is high, with a severity value of 8.8.
Amazon WorkSpaces agent below v1.0.1.1537 is affected by CVE-2021-43638.
Local attackers can exploit CVE-2021-43638 to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packets.
Yes, the fix for CVE-2021-43638 is to update the Amazon WorkSpaces agent to version 1.0.1.1537 or above.