CVE-2017-9450: Amazon Web Services Cloudformation Bootstrap

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The Amazon Web Services (AWS) CloudFormation bootstrap tools package (aka aws-cfn-bootstrap) before 1.4-19.10 allows local users to execute arbitrary code with root privileges by leveraging the ability to create files in an unspecified directory.

Affected products

  • Amazon Amazon Web Services Cloudformation Bootstrap: before 1.4-19.10 (fixed in 1.4-19.10)

Published 2017-10-30. Last modified 2026-06-17.