Impact
A vulnerability in AWS Tools for PowerShell before version 5.0.306 causes the tool to write sensitive data into log files, specifically the cleartext AWS Management Console password of an IAM user. This flaw is a case of improper handling of sensitive information (CWE-532) and permits a local user executing PowerShell commands to recover a valid IAM console password from command output and log artifacts, thereby compromising the confidentiality of that account.
Affected Systems
The affected product is AWS AWS Tools for PowerShell, any installation of a version earlier than 5.0.306. The issue is limited to the AWS Tools for PowerShell component and does not affect other AWS services or products.
Risk and Exploitability
The CVSS score of 6.7 indicates a moderate severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no known active exploitation. The likely attack vector is local execution – a malicious or compromised local user who can run PowerShell scripts has the ability to trigger the logging of sensitive credentials. Once the sensitive data is in logs, a local attacker can later retrieve it, potentially escalating privileges within the AWS account.
OpenCVE Enrichment