High severity7.0NVD Advisory· Published Apr 20, 2022· Updated Jun 17, 2026
CVE-2022-29527
CVE-2022-29527
Description
Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate privileges to root. This occurs in certain situations involving a race condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- Amazon AWS/amazon-ssm-agentdescription
- Range: <3.1.1208.0
- osv-coords8 versionspkg:rpm/opensuse/amazon-ssm-agent&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/amazon-ssm-agent&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/amazon-ssm-agent&distro=openSUSE%20Tumbleweedpkg:rpm/suse/amazon-ssm-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2012pkg:rpm/suse/amazon-ssm-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015pkg:rpm/suse/amazon-ssm-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP1pkg:rpm/suse/amazon-ssm-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP2pkg:rpm/suse/amazon-ssm-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP3
< 3.1.1260.0-150000.5.9.2+ 7 more
- (no CPE)range: < 3.1.1260.0-150000.5.9.2
- (no CPE)range: < 3.1.1260.0-150000.5.9.2
- (no CPE)range: < 3.1.1260.0-1.1
- (no CPE)range: < 3.1.1260.0-4.27.2
- (no CPE)range: < 3.1.1260.0-150000.5.9.2
- (no CPE)range: < 3.1.1260.0-150000.5.9.2
- (no CPE)range: < 3.1.1260.0-150000.5.9.2
- (no CPE)range: < 3.1.1260.0-150000.5.9.2
Patches
Vulnerability mechanics
References
3- github.com/aws/amazon-ssm-agent/commit/0fe8ae99b2ff25649c7b86d3bc05fc037400aca7nvdPatchThird Party Advisory
- github.com/aws/amazon-ssm-agent/releases/tag/3.1.1208.0nvdPatchRelease NotesThird Party Advisory
- bugzilla.suse.com/show_bug.cginvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.