Boletines de Vulnerabilidades

Reported AWS Desktop VPN Client for Windows Issue

   
Software afectado AmazonWS
 
Initial Publication Date: 2022/04/12 15:30 PST AWS is aware of the issues described in CVE-2022-25165 and CVE-2022-25166 relating to the AWS-provided Desktop VPN Client for Windows. These issues affect only client versions 2.0.0 and below; they have been addressed in version 3.0.0 and above. Note that these issues require existing code execution privileges and file access on the system running Desktop VPN Client for Windows. We recommend that customers upgrade to the latest version immediately

More info:

https://aws.amazon.com/security/security-bulletins/AWS-2022-005/