PT-2025-51281 · Unknown+1 · Harmonix On Aws+1

CVE-2025-14503

·

Publicado

2025-12-15

·

Atualizado

2025-12-21

CVSS v4.0

8.6

Alta

VetorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Harmonix on AWS versions 0.3.0 through 0.4.1
Description An overly-permissive IAM trust policy within the Harmonix on AWS framework could allow IAM principals within the same AWS account to escalate privileges through role assumption. The EKS environment provisioning role’s sample code is configured to trust the account root principal, potentially enabling any IAM principal in the same AWS account possessing sts:AssumeRole permissions to assume the role and gain administrative privileges.
Recommendations Upgrade to Harmonix on AWS version 0.4.2 or later.

Exploit

Correção

Incorrect Privilege Assignment

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-14503
GHSA-QM86-GQRQ-MQCW

Produtos afetados

Eks
Harmonix On Aws