High severity7.0NVD Advisory· Published Apr 20, 2022· Updated Jun 17, 2026
CVE-2022-29527
CVE-2022-29527
Description
Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate privileges to root. This occurs in certain situations involving a race condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11(expand)+ 2 more
- (no CPE)
- cpe:2.3:a:amazon:amazon_ssm_agent:*:*:*:*:*:*:*:*range: <3.1.1208.0
- (no CPE)range: <3.1.1208.0
- osv-coords8 versionspkg:rpm/suse/amazon-ssm-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015pkg:rpm/suse/amazon-ssm-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP3pkg:rpm/opensuse/amazon-ssm-agent&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/amazon-ssm-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP1pkg:rpm/opensuse/amazon-ssm-agent&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/amazon-ssm-agent&distro=openSUSE%20Tumbleweedpkg:rpm/suse/amazon-ssm-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP2pkg:rpm/suse/amazon-ssm-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2012
< 3.1.1260.0-150000.5.9.2+ 7 more
- (no CPE)range: < 3.1.1260.0-150000.5.9.2
- (no CPE)range: < 3.1.1260.0-150000.5.9.2
- (no CPE)range: < 3.1.1260.0-150000.5.9.2
- (no CPE)range: < 3.1.1260.0-150000.5.9.2
- (no CPE)range: < 3.1.1260.0-150000.5.9.2
- (no CPE)range: < 3.1.1260.0-1.1
- (no CPE)range: < 3.1.1260.0-150000.5.9.2
- (no CPE)range: < 3.1.1260.0-4.27.2
Patches
Vulnerability mechanics
References
3- github.com/aws/amazon-ssm-agent/commit/0fe8ae99b2ff25649c7b86d3bc05fc037400aca7nvdPatchThird Party Advisory
- github.com/aws/amazon-ssm-agent/releases/tag/3.1.1208.0nvdPatchRelease NotesThird Party Advisory
- bugzilla.suse.com/show_bug.cginvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.