Description

Improper Link Resolution Before File Access in the AWS VPN Client for macOS versions 1.3.2- 5.2.0 allows a local user to execute code with elevated privileges. Insufficient validation checks on the log destination directory during log rotation could allow a non-administrator user to create a symlink from a client log file to a privileged location. On log rotation, this could lead to code execution with root privileges if the user made crafted API calls which injected arbitrary code into the log file. We recommend users upgrade to AWS VPN Client for macOS 5.2.1 or the latest version.

INFO

Published Date :

2025-10-07T19:44:25.608Z

Last Modified :

2026-02-26T17:48:10.825Z

Source :

AMZN
AFFECTED PRODUCTS

The following products are affected by CVE-2025-11462 vulnerability.

Vendors Products
Amazon
  • Aws Client Vpn
Apple
  • Macos
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-11462.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact