CVE-2017-9450: Amazon Web Services Cloudformation Bootstrap
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The Amazon Web Services (AWS) CloudFormation bootstrap tools package (aka aws-cfn-bootstrap) before 1.4-19.10 allows local users to execute arbitrary code with root privileges by leveraging the ability to create files in an unspecified directory.
Affected products
- Amazon Amazon Web Services Cloudformation Bootstrap: before 1.4-19.10 (fixed in 1.4-19.10)
Published 2017-10-30. Last modified 2026-06-17.