Junglewise Threat Intelligence

CVE-2025-8904: Amazon EMR privilege escalation in Secret Agent component

CVE-2025-8904 · Severity: high · Published 2025-08-13

Technologies: Amazon AWS. Vendors: Amazon Web Services, Amazon.

Executive brief

Amazon EMR is a cloud-based platform used for processing and analyzing massive amounts of data. A security flaw was found in its Secret Agent component, which is responsible for managing sensitive credentials. An attacker with local access to the system could potentially steal security keys stored in a temporary directory, allowing them to gain unauthorized access to other data or systems.

Technical details

A privilege escalation vulnerability exists in the Amazon EMR Secret Agent component due to insecure storage of sensitive credentials. When features like Lake Formation, Apache Ranger, or Identity Center are enabled, the Secret Agent creates Kerberos keytab files in the /tmp/ directory. Because this directory is often world-readable or accessible to other local users, an attacker with local access to the cluster nodes can retrieve these files, decrypt the keys, and escalate their privileges. The vulnerability affects Amazon EMR versions 6.10 through 7.4. AWS has addressed this in version 7.5 by moving the staging directory for Kerberos credentials to a secure location.

Affected products

  • Amazon Web Services (AWS) EMR 6.10 through 7.4

Timeline

  • 2025-08-13: disclosed
  • 2025-08-13: patched: Fixed in Amazon EMR release 7.5

References

Related threats