VDB

GCVE-110-CLOUD-2023-0046

GCVE-110-CLOUD-2023-0046
Advisory Published
Vulnetix · Advisory published March 20, 2023
AWS Control Tower was not properly logging to CloudTrail when API calls failed due to a lack of permissions. This could have helped an adversary with existing access to a victim AWS environment avoid detection while enumerating privileges, since any unsuccessful API calls would not generate "access denied" log entries.

Affected Products

VendorProductVersionsPlatforms
AWSCloud Services
AWSControl Tower
AWSCloudTrail

Browse GCVE Records

74,657 records in the GCVE database · Updated July 24, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›