CVE-2025-0500: Issue affecting Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV clients
An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0500?
CVE-2025-0500 has been rated as a critical vulnerability due to its potential for man-in-the-middle attacks on remote sessions.
How do I fix CVE-2025-0500?
To fix CVE-2025-0500, update your Amazon WorkSpaces, Amazon AppStream 2.0, and Amazon DCV Clients to the latest versions provided by Amazon.
What versions are affected by CVE-2025-0500?
CVE-2025-0500 affects all versions of Amazon WorkSpaces, Amazon AppStream 2.0, and Amazon DCV Clients that leverage the DCV protocol.
What action should be taken if CVE-2025-0500 is exploited?
If CVE-2025-0500 is exploited, it is crucial to immediately update the affected clients and monitor for unauthorized access to remote sessions.
Is CVE-2025-0500 specific to certain Amazon services?
Yes, CVE-2025-0500 specifically affects the native clients for Amazon WorkSpaces, Amazon AppStream 2.0, and Amazon DCV Clients.