CVE-2024-30164: Buffer Overflow
Amazon AWS Client VPN has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated permissions. This is resolved in 3.11.1 on Windows, 3.9.1 on macOS, and 3.12.1 on Linux. NOTE: although the macOS resolution is the same as for CVE-2024-30165, this vulnerability on macOS is not the same as CVE-2024-30165.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30164?
CVE-2024-30164 has a high severity rating due to the potential for local execution of arbitrary commands with elevated permissions.
How do I fix CVE-2024-30164?
To fix CVE-2024-30164, upgrade to AWS Client VPN version 3.11.1 on Windows, 3.9.1 on macOS, or 3.12.1 on Linux.
What can exploit CVE-2024-30164?
CVE-2024-30164 can be exploited by a local actor who has access to the system running the affected version of AWS Client VPN.
What systems are affected by CVE-2024-30164?
CVE-2024-30164 affects AWS Client VPN versions prior to 3.11.1 for Windows, 3.9.1 for macOS, and 3.12.1 for Linux.
Is CVE-2024-30164 a remote or local vulnerability?
CVE-2024-30164 is a local vulnerability that requires access to the system to exploit.