amazon aws CVE-2022-25166 vulnerability in Amazon Products
Published on April 14, 2022

An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file paths for parameters (such as auth-user-pass). When this file is imported and the client attempts to validate the file path, it performs an open operation on the path and leaks the user's Net-NTLMv2 hash to an external server. This could be exploited by having a user open a crafted malicious ovpn configuration file.

NVD


Products Associated with CVE-2022-25166

stack.watch emails you whenever new vulnerabilities are published in Amazon Aws or Amazon Aws Client Vpn. Just hit a watch button to start following.

 
 

Exploit Probability

EPSS
1.14%
Percentile
78.15%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.