Published Tue, Sep 21st, 2021
Platforms
If a user with AWS WorkSpaces 3.0.10-3.1.8 installed visits a page in their web browser with attacker controlled content, the attacker can get zero click RCE under common circumstances.
Workspaces
Update client to 3.1.9 or higher
CVE-2021-38112
Contributed by https://github.com/0xdabbad00
Entry Status
Finalized
Disclosure Date
Tue, Sep 21st, 2021
Exploitability Period
-
Known ITW Exploitation
-
Detection Methods
None
Piercing Index Rating
-
Discovered by
David Yesland, Rhino Security