Impact
The vulnerability lies in the way the FPGA management tool installs itself; it creates a temporary file in a directory that the system marks as world‑writable and then, during installation, elevates privileges before reading that file. An attacker who can become a local user on the host can pre‑create malicious shell content at the predictable location, which will be executed with root privileges when the installer runs. This represents a classic local privilege escalation flaw covered by CWE‑379.
Affected Systems
The vector affects the AWS FPGA Development Kit across all deployments of the aws-fpga component before release 2.3.4. Users running any older AWS FPGA Development Kit version inherit this weakness, while those on 2.3.4 or newer are immune.
Risk and Exploitability
With a CVSS score of 7.3, the exploit presents a high risk to affected systems when a local user gains the ability to run arbitrary code locally. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the absence of an exploit database entry does not eliminate the inherent local threat. The attack requires local access and the privilege‑elevating installer step; successful exploitation would allow any local user to execute arbitrary code as root.
OpenCVE Enrichment