CVE-2026-7791
7.8Amazon · WorkSpaces for Windows
Improper privilege management in Amazon WorkSpaces for Windows allows local authenticated users to achieve local privilege escalation to SYSTEM.
Executive summary
An improper privilege management vulnerability in Amazon WorkSpaces for Windows before version 2.6.2034.0 allows local authenticated users to escalate privileges to SYSTEM.
Vulnerability
This flaw involves improper privilege management within the log rotation mechanism of the Skylight Workspace Config Service, requiring local authenticated user privileges to trigger.
Business impact
A successful exploitation of this vulnerability permits a local user to gain full SYSTEM privileges on the affected host, leading to complete system compromise. With a CVSS score of 7.8, the high severity reflects the potential for total loss of confidentiality, integrity, and availability at the local operating system level, threatening organizational endpoints.
Remediation
Immediate Action: Update Amazon WorkSpaces for Windows to version 2.6.2034.0 or later to resolve the underlying privilege management flaw.
Proactive Monitoring: Monitor endpoint logs for suspicious local file creation activities or unauthorized process executions stemming from standard user accounts.
Compensating Controls: Restrict local user access privileges on managed endpoints using the principle of least privilege to minimize exposure to local privilege escalation vectors.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept repository exists on GitHub (https://github.com/BenZamir/CVE-2026-7791).
Analyst recommendation
Given the severity of potential local privilege escalation to SYSTEM, administrators should prioritize updating Amazon WorkSpaces to version 2.6.2034.0 across all applicable endpoints. Promptly deploying the vendor update remains the most effective measure to prevent unauthorized administrative access.