Impact
The vulnerability occurs in the aws:downloadContent plugin of amazon-ssm-agent, where the plugin does not correctly constrain the pathname used to write downloaded files. An authenticated remote user who can send the AWS-DownloadContent SSM document can supply a maliciously crafted object key that causes the agent to write files outside the intended download directory. This flaw can lead to overwriting critical system files and executing arbitrary code with root privileges.
Affected Systems
The issue affects installations of amazon-ssm-agent prior to version 3.3.4515.0 on Amazon Web Services environments. Any host running this agent and capable of receiving the AWS-DownloadContent document with S3 source references is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.7 reflects a high severity due to privilege escalation and code execution potential. The EPSS score is not available, so the likelihood of exploitation is uncertain, but the vulnerability is not listed in the CISA KEV catalog. Attackers need authenticated access to the SSM SendCommand service with the AWS-DownloadContent document permission and the ability to specify crafted S3 object keys. If obtained, this can result in root-level compromise of the host.
OpenCVE Enrichment