AWS Client VPN for macOS Hit by Critical Privilege Escalation Vulnerability
Amazon Web Services (AWS) has released bulletin AWS-2025-020, which outlines a critical vulnerability in the macOS version of its Client VPN software.
Amazon Web Services (AWS) has released bulletin AWS-2025-020, which outlines a critical vulnerability in the macOS version of its Client VPN software.
The vulnerability, identified as CVE-2025-11462, is due to the VPN client's failure to validate the log destination directory during log rotation.
CVE ID Affected Products Impact Exploit Prerequisites CVSS 3.1 Score
CVE-2025-11462 AWS Client VPN Client for macOS versions 1.3.2–5.2.0 Local privilege escalation to root on macOS devices Local non-administrator user access, ability to create symlinks in client log directory Not disclosed
Exploitation of this vulnerability allows a local user to gain full root privileges on a macOS device. This could enable threat actors with minimal initial access to control infected machines, bypass sandbox restrictions, install persistent malware, or access sensitive data.
Amazon Web Services (AWS) has released bulletin AWS-2025-020, which outlines a critical vulnerability in the macOS version of its Client VPN software.
In environments utilizing AWS Client VPN extensively, compromised endpoints may lead to unauthorized access to on-premises resources or failures in tenant isolation. The vulnerability is considered critical for all macOS users of the service due to its high potential impact and ease of exploitation via built-in APIs.
AWS has resolved the issue in Client VPN Client version 5.2.1. It is imperative for administrators and users to update to this patched version immediately.
In automated environments, the update should be integrated into configuration management and orchestration pipelines without delay. No workarounds are available, so upgrading is the only effective measure against this threat.
Security teams should inspect endpoint monitoring logs for unusual privilege escalation events and may consider temporarily tightening macOS user access controls until devices are updated. Consistently staying current with AWS updates is crucial for safeguarding macOS endpoints in cloud environments.
Vigilance and prompt patch deployment are essential defenses against the exploitation of this critical vulnerability.
Based on reporting by GBHackers.
