First published: Wed Jan 15 2025(Updated: )
An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle.
Credit: ff89ba41-3aa1-4d27-914a-91399e9639e5
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon WorkSpaces Client | ||
Amazon AppStream 2.0 | ||
Amazon DCV Clients |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0500 has been rated as a critical vulnerability due to its potential for man-in-the-middle attacks on remote sessions.
To fix CVE-2025-0500, update your Amazon WorkSpaces, Amazon AppStream 2.0, and Amazon DCV Clients to the latest versions provided by Amazon.
CVE-2025-0500 affects all versions of Amazon WorkSpaces, Amazon AppStream 2.0, and Amazon DCV Clients that leverage the DCV protocol.
If CVE-2025-0500 is exploited, it is crucial to immediately update the affected clients and monitor for unauthorized access to remote sessions.
Yes, CVE-2025-0500 specifically affects the native clients for Amazon WorkSpaces, Amazon AppStream 2.0, and Amazon DCV Clients.