QID 376376
Date Published: 2022-02-07
QID 376376: Amazon AWS WorkSpace Remote Code Execution (RCE) Vulnerability
Amazon WorkSpaces is a fully managed desktop virtualization service that enables you to securely access data and applications from any supported device.
Affected Version:
Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows
QID Detection Logic: (Authenticated).
It checks file versions to check for the vulnerable version.
In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote code execution because of the Chromium Embedded Framework (CEF) --gpu-launcher argument.
Solution
Customers are advised to upgrade to version Amazon AWS WorkSpaces
Vendor References
CVEs related to QID 376376
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Amazon AWS WorkSpaces |
|