VDB
CVE-2022-29527
CVE-2022-29527
PUBLISHED
CVSS 6.900000095367432 MEDIUM
Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate privileges to root. This occurs in certain situations involving a race condition.
EPSS 0.15% · 35.6th percentile
Risk Scores
CVSS 2.0
6.900000095367432
EPSS Score
0.15%
35.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| amazon | amazon_ssm_agent | 0 |
Timeline
- Apr 20, 2022 CVE Published
- Apr 21, 2022 EPSS Score
- Jun 10, 2022 EPSS Score
- Jul 31, 2022 EPSS Score
- Sep 19, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
- Dec 28, 2022 EPSS Score
- Feb 16, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 7, 2023 EPSS Score
- May 27, 2023 EPSS Score
- Jul 16, 2023 EPSS Score