Tag: Amazon EC2

Amazon EC2 SSM Agent Flaw Patched After Privilege Escalation via Path Traversal
News

Amazon EC2 SSM Agent Flaw Patched After Privilege Escalation via Path Traversal

Details of a now-patched security vulnerability in the Amazon EC2 Simple Systems Manager (SSM) Agent have been made public by cybersecurity experts. If exploited successfully, the vulnerability may allow an attacker to execute code and escalate privileges. According to a report shared with The Hacker News, Cymulate stated that the vulnerability could allow an attacker to write files to sensitive areas of the system, execute arbitrary scripts with root privileges, and create directories in unexpected places on the filesystem. Administrators can remotely manage, configure, and run commands on EC2 instances and on-premises servers with the help of Amazon SSM Agent, a feature of Amazon Web Services (AWS). The software executes instructions and actions specified in SSM Documents, whic...