Vulnerabilities (CVE)

Filtered by vendor Amazon
Filtered by product Cloudwatch Agent
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-23511 2 Amazon, Microsoft 2 Cloudwatch Agent, Windows 2024-11-21 N/A 7.1 HIGH
A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2 instances and on-premises servers, in versions up to and including v1.247354. When users trigger a repair of the Agent, a pop-up window opens with SYSTEM permissions. Users with administrative access to affected hosts may use this to create a new command prompt as NT AUTHORITY\SYSTEM. To trigger this issue, the third party must be able to access the affecte ...

Show More