First published: Wed Jan 15 2025(Updated: )
An issue in the native clients for Amazon WorkSpaces (when running PCoIP protocol) may allow an attacker to access remote sessions via man-in-the-middle.
Credit: ff89ba41-3aa1-4d27-914a-91399e9639e5
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon WorkSpaces |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0501 is rated as a critical vulnerability due to the potential for unauthorized access to remote sessions.
To fix CVE-2025-0501, update the Amazon WorkSpaces Client to the latest version that includes the security patch.
CVE-2025-0501 can allow attackers to intercept and access sensitive data during remote sessions using the PCoIP protocol.
CVE-2025-0501 affects all versions of Amazon WorkSpaces Client that utilize the PCoIP protocol prior to the security patch release.
While there are indications of potential exploitation, proper patching can mitigate the risks associated with CVE-2025-0501.