🛡️ CVE-2022-23511 — cloudwatch-agent
Description
Amazon CloudWatch Agent for Windows has Privilege Escalation Vector
Impact
A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows in versions up to and including v1.247354. When users trigger a repair of the Agent, a pop-up window opens with SYSTEM permissions. Users with administrative access to affected hosts may use this to create a new command prompt as NT AUTHORITY\SYSTEM.
To trigger this issue, the third party must be able to access the affected host and elevate their privileges such that they’re able to trigger the agent repair process. They must also be able to install the tools required to trigger the issue.
This issue does not affect the CloudWatch Agent for macOS or Linux.
Patches
Maintainers recommend that Agent users upgrade to the latest available version of the CloudWatch Agent to address this issue.
Workarounds
There is no recommended work around. Affected users must update the installed version of the CloudWatch Agent to address this issue.
References
https://github.com/aws/amazon-cloudwatch-agent/commit/6119858864c317ff26f41f576c169148d1250837
For more information
If you have any questions or comments about this advisory, contact AWS/Amazon Security via their [vulnerability reporting page](http://aws.amazon.com/security/vulnerability-reporting/) or directly via email to [[email protected]](mailto:[email protected]). Please do not create a public GitHub issue.
How this vulnerability can be exploited
This issue can be reached over the network, attack complexity is high, an attacker needs low-level privileges on the target. A user must be tricked into taking some action. The scope is changed, meaning a successful attack can affect components beyond the vulnerable one. Rated impact: confidentiality high, integrity low, availability low.
Weakness class
CVE-2022-23511 is classified as CWE-274: Improper Handling of Insufficient Privileges. The product does not handle or incorrectly handles when it has insufficient privileges to perform an operation, leading to resultant weaknesses.
Affected software
CVE-2022-23511 is recorded against 2 packages.
- cloudwatch-agent (fixed in 1.247355)
- github.com/aws/amazon-cloudwatch-agent
Timeline and source
Published on 12 December 2022 and last revised on 17 June 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from NVD.
References
Details
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:L
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| cloudwatch-agent | — | 1.247355 |
| github.com/aws/amazon-cloudwatch-agent | — | — |
References
Site Security Check
Is cloudwatch-agent part of your stack?
CVE-2022-23511 is rated CVSS 8.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.