Junglewise Threat Intelligence

CVE-2025-8069: AWS Client VPN local privilege escalation in Windows client

CVE-2025-8069 · Severity: high · Published 2025-07-23

Technologies: Amazon AWS. Vendors: AWS, Amazon.

Executive brief

AWS Client VPN is a tool used by employees to securely connect to corporate networks and cloud resources. A security flaw in the Windows version of this software allows a standard user to gain full administrative control over a computer. This occurs if a standard user places a malicious file on the system before an administrator attempts to install or update the VPN software.

Technical details

A local privilege escalation vulnerability exists in the AWS Client VPN Windows client due to an insecure default search path for OpenSSL configuration. During installation, the process attempts to load an OpenSSL configuration file from a hardcoded, non-existent path: C:\usr\local\windows-x86_64-openssl-localbuild\ssl. A low-privileged local attacker can create this directory structure and place a malicious configuration file or library within it. When an administrator subsequently runs the installer, the malicious code is executed with SYSTEM/root-level privileges. This issue is resolved in version 5.2.2.

Affected products

  • AWS Client VPN Windows Client 4.1.0, 5.0.0, 5.0.1, 5.0.2, 5.1.0, 5.2.0, 5.2.1

Timeline

  • 2025-07-23: disclosed
  • 2025-07-23: patched: Fixed in version 5.2.2

References

Related threats