Amazon Web Services (AWS) has recently fixed two major security vulnerabilities in its cloud services: Amazon WorkSpaces, Amazon AppStream 2.0, and Amazon DCV (Desktop Cloud Visualization).
Vulnerabilities CVE-2025-0500 and CVE-2025-0501 could let attackers conduct man-in-the-middle attacks and access remote sessions without permission.
By infosecbulletin
/ Tuesday , February 18 2025
Indian government and educational websites, along with reputable financial brands, have experienced SEO poisoning, causing user traffic to be redirected...
Read More
By infosecbulletin
/ Tuesday , February 18 2025
The Cyber Threat Intelligence Unit of BGD e-GOV CIRT has found 600 vulnerable PRTG instances in Bangladesh, affected by the...
Read More
By infosecbulletin
/ Monday , February 17 2025
Amazon Web Services (AWS) has been named in an FIR after a builder claimed damages to the tune of Rs...
Read More
By infosecbulletin
/ Monday , February 17 2025
CISA has issued an urgent warning about a critical zero-day vulnerability in Apple iOS and iPadOS, known as CVE-2025-24200, which...
Read More
By infosecbulletin
/ Monday , February 17 2025
A major IoT data breach has exposed 2.7 billion records, including Wi-Fi network names, passwords, IP addresses, and device IDs....
Read More
By infosecbulletin
/ Sunday , February 16 2025
A serious authentication bypass vulnerability in SonicWall firewalls, called CVE-2024-53704, is currently being exploited, according to cybersecurity firms. The increase...
Read More
By infosecbulletin
/ Sunday , February 16 2025
AMD has released security patches for two high-severity vulnerabilities in its System Management Mode (SMM). If exploited, these could let...
Read More
By infosecbulletin
/ Sunday , February 16 2025
Lazarus Group has initiated a complex global campaign aimed at software developers and cryptocurrency users. Operation Marstech Mayhem uses the...
Read More
By infosecbulletin
/ Saturday , February 15 2025
Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data breaches, website defacement and so...
Read More
By infosecbulletin
/ Saturday , February 15 2025
RedMike (Salt Typhoon) targeted university devices in Bangladesh, likely to access research in telecommunications, engineering, and technology, especially from institutions...
Read More
CVE-2025-0500 impacts certain versions of Amazon WorkSpaces native clients, Amazon AppStream 2.0, and Amazon DCV. It has a CVSS v4.0 score of 7.7, signifying high severity.
This vulnerability impacts various client versions across all the major platforms.
CVE-2025-0501 specifically targets Amazon WorkSpaces clients using the PCoIP protocol.
Amazon security experts found a vulnerability affecting Windows, macOS, Linux, and Android clients, which could allow unauthorized access to remote WorkSpaces sessions.
Technical Analysis:
For CVE-2025-0500: Users should upgrade to Amazon WorkSpaces client version 5.21.0 or later for Windows and macOS, and version 2024.2 or later for Linux. Amazon AppStream 2.0 users need version 1.1.1332 or later, and Amazon DCV users should update to version 2023.1.9127 or later.
For CVE-2025-0501: AWS advises to update to the latest Amazon WorkSpaces client for your operating system.
Security experts stress the need for immediate updates to client software for users and organizations. These vulnerabilities highlight the ongoing challenges of securing cloud services and remote work solutions.
With increasing cloud adoption, users should stay alert and regularly update their software to reduce security risks. AWS has informed customers about the end of support for affected versions and is closely monitoring the situation.