CVE-2022-25165 is a Time-of-Check to Time-of-Use (TOCTOU) race condition in Amazon AWS VPN Client 2.0.0. This flaw allows a low-level user to inject dangerous parameters into VPN configuration files, leading to an arbitrary file write as SYSTEM with partial control over content. With a CVSS score of 7.0 (High), this vulnerability requires local access and high attack complexity, but can result in complete compromise of confidentiality, integrity, and availability. There is currently no evidence of active exploitation, and no public exploit code is available, though it has garnered minor community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.0CPE matchmatch criteria | cpe:2.3:a:amazon:aws_client_vpn:2.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.