CVSS 3.1 Score 7.5 of 10 (high)


Published Jun 11, 2024
CWE ID 266


CVE-2024-37293 is a vulnerability affecting the AWS Deployment Framework (ADF), a tool used to manage and deploy resources across multiple AWS accounts and regions. The vulnerability exists in the ADF bootstrap process, which relies on elevated privileges to deploy ADF's bootstrap stacks. There are two versions of the bootstrap process, one using AWS CodeBuild and the other using AWS Lambda. If an attacker has permissions to modify the behavior of either the CodeBuild project or the Lambda function, they can potentially escalate their privileges. This vulnerability has a high base severity rating, with a CVSS score of 7.5, and poses a risk to organizations in terms of confidentiality and integrity impact.

Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.


Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-37293 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions