bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: slwsconfigservice

show all
Thursday, August 20, 2026

Amazon WorkSpaces Skylight Agent Privilege Escalation Flaw Needs Immediate Patching

Amazon WorkSpaces Skylight Workspace Config Service (slwsconfigservice) has a nasty local privilege escalation vulnerability (CVE-2026-7791) that lets authenticated non-admin users jump to SYSTEM level through a race condition in log archival. If you're running versions below 2.6.2034.0 on Windows, you need to update ASAP—this one requires your action. The flaw affects a critical background service handling config and health monitoring.

source: [aws/security-bulletin]