aws.amazon.comVendor advisory
https://aws.amazon.com/security/security-bulletins/AWS-2025-017 CVE-2025-8904
CRITICAL
Privilege escalation issue in Amazon EMR Secret Agent component
Record summary
CVE-2025-8904 has a selected CVSS score of 9.0 (critical).
Description
Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory and another account can potentially decrypt the keys and escalate to higher privileges. Users are advised to upgrade to Amazon EMR version 7.5 or higher. For Amazon EMR releases between 6.10 and 7.4, we strongly recommend that you run the bootstrap script and RPM files with the fix provided in the location below.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 15, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | 6.10 to < 7.4 | affected |
References
5docs.aws.amazon.comrelease notespatch
https://docs.aws.amazon.com/emr/latest/ReleaseGuide/emr-750-release.html docs.aws.amazon.com
https://docs.aws.amazon.com/emr/latest/ReleaseGuide/emr-release-app-versions-7.x.html github.comThird-party advisory
https://github.com/advisories/GHSA-hf8h-76fm-735v nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-8904