Amazon Web Services (AWS) has recently fixed two major security vulnerabilities in its cloud services: Amazon WorkSpaces, Amazon AppStream 2.0, and Amazon DCV (Desktop Cloud Visualization).
Vulnerabilities CVE-2025-0500 and CVE-2025-0501 could let attackers conduct man-in-the-middle attacks and access remote sessions without permission.
By infosecbulletin
/ Friday , July 11 2025
AMD has revealed four new vulnerabilities that could enable attackers to access sensitive data via timing-based side-channel attacks. These vulnerabilities,...
Read More
By infosecbulletin
/ Thursday , July 10 2025
GitLab has released security updates for its Community Edition (CE) and Enterprise Edition (EE) to fix vulnerabilities that could enable...
Read More
By infosecbulletin
/ Thursday , July 10 2025
A newly found vulnerability (CVE-2025-7206) in the D-Link DIR-825 router firmware version 2.10 poses a significant risk to home and...
Read More
By infosecbulletin
/ Thursday , July 10 2025
Zoom released a security update addressing six newly discovered vulnerabilities in its Workplace, Rooms, and SDK products for Windows, macOS,...
Read More
By infosecbulletin
/ Wednesday , July 9 2025
Jack Dorsey, co-founder of Twitter and Block Head, launched a new peer-to-peer messaging app called Bitchat, which operates solely over...
Read More
By infosecbulletin
/ Wednesday , July 9 2025
Splunk has issued critical security updates for SOAR versions 6.4.0 and 6.4 to fix several vulnerabilities in third-party packages. The...
Read More
By infosecbulletin
/ Wednesday , July 9 2025
Cybersecurity researcher Jeremiah Fowler found an unsecured database with 245,949 records, reported to vpnMentor. It likely belonged to a tax...
Read More
By infosecbulletin
/ Wednesday , July 9 2025
Fortinet has issued a critical patch for a critical vulnerability in its FortiWeb product, a web application firewall commonly used...
Read More
By infosecbulletin
/ Wednesday , July 9 2025
Microsoft's Patch Tuesday in July 2025 is critical, featuring updates for 137 vulnerabilities, including a zero-day in Microsoft SQL Server....
Read More
By infosecbulletin
/ Tuesday , July 8 2025
ThreatFabric researchers have discovered a new sophisticated campaign by the Anatsa banking trojan targeting mobile banking users in the U.S....
Read More
CVE-2025-0500 impacts certain versions of Amazon WorkSpaces native clients, Amazon AppStream 2.0, and Amazon DCV. It has a CVSS v4.0 score of 7.7, signifying high severity.
This vulnerability impacts various client versions across all the major platforms.
CVE-2025-0501 specifically targets Amazon WorkSpaces clients using the PCoIP protocol.
Amazon security experts found a vulnerability affecting Windows, macOS, Linux, and Android clients, which could allow unauthorized access to remote WorkSpaces sessions.
Technical Analysis:
For CVE-2025-0500: Users should upgrade to Amazon WorkSpaces client version 5.21.0 or later for Windows and macOS, and version 2024.2 or later for Linux. Amazon AppStream 2.0 users need version 1.1.1332 or later, and Amazon DCV users should update to version 2023.1.9127 or later.
For CVE-2025-0501: AWS advises to update to the latest Amazon WorkSpaces client for your operating system.
Security experts stress the need for immediate updates to client software for users and organizations. These vulnerabilities highlight the ongoing challenges of securing cloud services and remote work solutions.
With increasing cloud adoption, users should stay alert and regularly update their software to reduce security risks. AWS has informed customers about the end of support for affected versions and is closely monitoring the situation.