ZDI-25-205: Amazon AWS CloudFormation Templates Uncontrolled Search Path Element Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Amazon AWS. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-205?
The severity of ZDI-25-205 is rated at 9.8 on the CVSS scale, indicating critical risk.
What causes the ZDI-25-205 vulnerability?
The ZDI-25-205 vulnerability is caused by a flaw in Amazon AWS that allows remote code execution without authentication.
How do I fix ZDI-25-205?
To fix ZDI-25-205, ensure that all affected AWS CloudFormation instances are updated with the latest security patches provided by Amazon.
Which software is affected by ZDI-25-205?
ZDI-25-205 specifically affects installations of Amazon AWS CloudFormation.
Can ZDI-25-205 be exploited remotely?
Yes, ZDI-25-205 can be exploited remotely, allowing attackers to execute arbitrary code without requiring authentication.