Amazon Web Services (AWS) has recently fixed two major security vulnerabilities in its cloud services: Amazon WorkSpaces, Amazon AppStream 2.0, and Amazon DCV (Desktop Cloud Visualization).
Vulnerabilities CVE-2025-0500 and CVE-2025-0501 could let attackers conduct man-in-the-middle attacks and access remote sessions without permission.
By infosecbulletin
/ Sunday , June 29 2025
Doctors at Columbia University Fertility Center have reported what they are calling the first pregnancy using a new AI system,...
Read More
By infosecbulletin
/ Saturday , June 28 2025
Cybersecurity experts and federal authorities are warning that the Scattered Spider hackers are now targeting aviation and transportation, indicating a...
Read More
By F2
/ Saturday , June 28 2025
Since June 9, 2025, Russian users connecting to Cloudflare services have faced throttling by ISPs. As the throttling is being...
Read More
By infosecbulletin
/ Saturday , June 28 2025
A new report from SafetyDetectives reveals that hackers posted a massive 3.1GB dataset online, containing about 61 million records reportedly...
Read More
By infosecbulletin
/ Friday , June 27 2025
A 30-year-old robotics engineer from Chennai set off alarm bells in 11 states by allegedly sending hoax bomb threats. She...
Read More
By infosecbulletin
/ Friday , June 27 2025
Cisco has issued updates to fix two critical security vulnerabilities in Identity Services Engine (ISE) and ISE Passive Identity Connector...
Read More
By F2
/ Thursday , June 26 2025
CISA warns about a serious vulnerability in Fortinet FortiOS that threatens network security. CISA included CVE-2019-6693 in its Known Exploited...
Read More
By F2
/ Thursday , June 26 2025
Rapid7 has revealed serious vulnerabilities in multifunction printers (MFPs) from Brother, FUJIFILM, Ricoh, and Toshiba Tec Corporation. These findings, covering...
Read More
By infosecbulletin
/ Wednesday , June 25 2025
Citrix has issued security updates for a critical vulnerability in NetScaler ADC that has been actively exploited. The vulnerability CVE-2025-6543...
Read More
By F2
/ Wednesday , June 25 2025
SonicWall warned on Monday that unknown attackers have trojanized its SSL-VPN NetExtender application, tricking users into downloading it from fake...
Read More
CVE-2025-0500 impacts certain versions of Amazon WorkSpaces native clients, Amazon AppStream 2.0, and Amazon DCV. It has a CVSS v4.0 score of 7.7, signifying high severity.
This vulnerability impacts various client versions across all the major platforms.
CVE-2025-0501 specifically targets Amazon WorkSpaces clients using the PCoIP protocol.
Amazon security experts found a vulnerability affecting Windows, macOS, Linux, and Android clients, which could allow unauthorized access to remote WorkSpaces sessions.
Technical Analysis:
For CVE-2025-0500: Users should upgrade to Amazon WorkSpaces client version 5.21.0 or later for Windows and macOS, and version 2024.2 or later for Linux. Amazon AppStream 2.0 users need version 1.1.1332 or later, and Amazon DCV users should update to version 2023.1.9127 or later.
For CVE-2025-0501: AWS advises to update to the latest Amazon WorkSpaces client for your operating system.
Security experts stress the need for immediate updates to client software for users and organizations. These vulnerabilities highlight the ongoing challenges of securing cloud services and remote work solutions.
With increasing cloud adoption, users should stay alert and regularly update their software to reduce security risks. AWS has informed customers about the end of support for affected versions and is closely monitoring the situation.