Critical AWS ClientVPN for macOS Vulnerability Let Attackers Escalate Privileges
A critical vulnerability has been identified in the AWS Client VPN for macOS, posing a local privilege escalation risk for non-administrator users. This vulnerability, designated as CVE-2025-11462, allows attackers to gain root access by exploiting the…
A critical vulnerability has been identified in the AWS Client VPN for macOS, posing a local privilege escalation risk for non-administrator users. This vulnerability, designated as CVE-2025-11462, allows attackers to gain root access by exploiting the client's log rotation mechanism.
AWS Client VPN macOS Client LPE Vulnerability
The issue affects macOS client versions 1.3.2 through 5.2.0, where improper validation of the log destination directory during automatic log rotation permits a local, non-administrator account to create a symbolic link from the generated log file to a privileged system location, such as /etc/crontab.
An attacker can use an internal API endpoint to write log entries, allowing them to inject arbitrary content into the symlinked file. Upon log rotation, crafted content as a valid cron job executes with root privileges at the next cron interval. This issue does not affect Windows and Linux clients.
Affected Products AWS Client VPN Client for macOS versions 1.3.2 through 5.2.0
A critical vulnerability has been identified in the AWS Client VPN for macOS, posing a local privilege escalation risk for non-administrator users.
Impact Local privilege escalation to root privileges
Exploit Prerequisites Local, non-administrator user on a vulnerable macOS host
CVSS 3.1 Score 7.8 (High)
AWS has addressed CVE-2025-11462 in AWS Client VPN Client version 5.2.1. Users operating versions from 1.3.2 to 5.2.0 should upgrade immediately to mitigate this vulnerability.
Since no effective workaround exists, prompt upgrading is essential. Administrators are advised to verify client software versions and ensure the presence of version 5.2.1 or later. Due to the high severity of CVSS 3.1 score 7.8, organizations using AWS Client VPN on macOS should prioritize patch deployment and audit log directories for unauthorized symbolic links.
Based on reporting by Cyber Security News.
