Executive brief
AWS Client VPN is a service that allows employees to securely connect to corporate resources and cloud infrastructure. A security flaw in the macOS version of the client software could allow a standard user to gain full administrative (root) control over their computer. This could lead to unauthorized access to sensitive local data or the installation of persistent malicious software on the device.
Technical details
A local privilege escalation vulnerability exists in the AWS Client VPN macOS client (versions 1.3.2 through 5.2.0) due to improper validation of the log destination directory during log rotation. A local, non-privileged attacker can create a symbolic link from a client log file to a privileged system location, such as a Crontab file. By subsequently triggering an internal API with arbitrary inputs, the attacker can force the application to write those inputs into the privileged location during the log rotation process. This allows for arbitrary code execution with root privileges. The issue is resolved in version 5.2.1.
Affected products
- AWS Client VPN Client 1.3.2 through 5.2.0
Timeline
- 2025-10-07: disclosed
- 2025-10-07: patched: Fixed in version 5.2.1