ZDI-25-206: Amazon AWS CloudFormation Templates Uncontrolled Search Path Element Remote Code Execution Vulnerability
Published Apr 7, 2025
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Amazon AWS. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8.
Affected Software
1 affected component
Amazon AWS CloudFormation
Event History
Apr 7, 2025
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-25-206?
The vulnerability ZDI-25-206 has a CVSS rating of 9.8, indicating critical severity.
2
What can attackers do with ZDI-25-206?
Remote attackers can execute arbitrary code on affected installations of Amazon AWS due to ZDI-25-206.
3
Is authentication required to exploit ZDI-25-206?
No, authentication is not required to exploit the ZDI-25-206 vulnerability.
4
Which software is affected by ZDI-25-206?
ZDI-25-206 affects Amazon AWS CloudFormation installations.
5
How can I mitigate ZDI-25-206?
To mitigate ZDI-25-206, apply the latest security patches and updates provided by Amazon for AWS CloudFormation.