CVE-2026-7791

7.8

Amazon · WorkSpaces for Windows

Improper privilege management in Amazon WorkSpaces for Windows allows local authenticated users to achieve local privilege escalation to SYSTEM.

Executive summary

An improper privilege management vulnerability in Amazon WorkSpaces for Windows before version 2.6.2034.0 allows local authenticated users to escalate privileges to SYSTEM.

Vulnerability

This flaw involves improper privilege management within the log rotation mechanism of the Skylight Workspace Config Service, requiring local authenticated user privileges to trigger.

Business impact

A successful exploitation of this vulnerability permits a local user to gain full SYSTEM privileges on the affected host, leading to complete system compromise. With a CVSS score of 7.8, the high severity reflects the potential for total loss of confidentiality, integrity, and availability at the local operating system level, threatening organizational endpoints.

Remediation

Immediate Action: Update Amazon WorkSpaces for Windows to version 2.6.2034.0 or later to resolve the underlying privilege management flaw.

Proactive Monitoring: Monitor endpoint logs for suspicious local file creation activities or unauthorized process executions stemming from standard user accounts.

Compensating Controls: Restrict local user access privileges on managed endpoints using the principle of least privilege to minimize exposure to local privilege escalation vectors.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept repository exists on GitHub (https://github.com/BenZamir/CVE-2026-7791).

Analyst recommendation

Given the severity of potential local privilege escalation to SYSTEM, administrators should prioritize updating Amazon WorkSpaces to version 2.6.2034.0 across all applicable endpoints. Promptly deploying the vendor update remains the most effective measure to prevent unauthorized administrative access.

More Amazon CVEs

Sources