CVE-2022-25166

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
14/04/2022
Last modified:
23/04/2022

Description

An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file paths for parameters (such as auth-user-pass). When this file is imported and the client attempts to validate the file path, it performs an open operation on the path and leaks the user's Net-NTLMv2 hash to an external server. This could be exploited by having a user open a crafted malicious ovpn configuration file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:amazon:aws_client_vpn:2.0.0:*:*:*:*:*:*:*