Amazon Web Services (AWS) has recently fixed two major security vulnerabilities in its cloud services: Amazon WorkSpaces, Amazon AppStream 2.0, and Amazon DCV (Desktop Cloud Visualization).
Vulnerabilities CVE-2025-0500 and CVE-2025-0501 could let attackers conduct man-in-the-middle attacks and access remote sessions without permission.
By infosecbulletin
/ Thursday , April 17 2025
On Wednesday, CISA alerted about increased breach risks due to the earlier compromise of legacy Oracle Cloud servers, emphasizing the...
Read More
By infosecbulletin
/ Thursday , April 17 2025
Cisco issued a security advisory about a serious vulnerability in its Webex App that allows unauthenticated remote code execution (RCE)...
Read More
By infosecbulletin
/ Thursday , April 17 2025
On Wednesday, Apple released urgent operating system updates to address two security vulnerabilities that had already been exploited in highly...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
On April 15, 2025, Oracle released a Critical Patch Update for 378 flaws for its products. The patch update covers...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
Check Point Research warns of the active exploitation of a new vulnerability, CVE-2025-24054, which lets hackers leak NTLMv2-SSP hashes using...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
Bengaluru's Whiteboard Technologies Pvt Ltd was hit by a ransomware attack, with hackers demanding a ransom of up to $70,000...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
MITRE Vice President Yosry Barsoum warned that U.S. government funding for the Common Vulnerabilities and Exposures (CVE) and Common Weakness...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
PwC has ceased operations in more than a dozen countries that its global bosses have deemed too small, risky or...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
The Australian Cyber Security Centre (ACSC) has alerted technical users in both private and public sectors about ongoing exploitation of...
Read More
By infosecbulletin
/ Tuesday , April 15 2025
Cybersecurity platform ANY.RUN recently reported the top 10 malware threats of the week, highlighting a surge in activity for information...
Read More
CVE-2025-0500 impacts certain versions of Amazon WorkSpaces native clients, Amazon AppStream 2.0, and Amazon DCV. It has a CVSS v4.0 score of 7.7, signifying high severity.
This vulnerability impacts various client versions across all the major platforms.
CVE-2025-0501 specifically targets Amazon WorkSpaces clients using the PCoIP protocol.
Amazon security experts found a vulnerability affecting Windows, macOS, Linux, and Android clients, which could allow unauthorized access to remote WorkSpaces sessions.
Technical Analysis:
For CVE-2025-0500: Users should upgrade to Amazon WorkSpaces client version 5.21.0 or later for Windows and macOS, and version 2024.2 or later for Linux. Amazon AppStream 2.0 users need version 1.1.1332 or later, and Amazon DCV users should update to version 2023.1.9127 or later.
For CVE-2025-0501: AWS advises to update to the latest Amazon WorkSpaces client for your operating system.
Security experts stress the need for immediate updates to client software for users and organizations. These vulnerabilities highlight the ongoing challenges of securing cloud services and remote work solutions.
With increasing cloud adoption, users should stay alert and regularly update their software to reduce security risks. AWS has informed customers about the end of support for affected versions and is closely monitoring the situation.