Cyber Posture

CVE-2025-0501

High

Published: 15 January 2025

Published
15 January 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.0021 42.4th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

An issue in the native clients for Amazon WorkSpaces (when running PCoIP protocol) may allow an attacker to access remote sessions via man-in-the-middle.

Security Summary

CVE-2025-0501 is a vulnerability in the native clients for Amazon WorkSpaces when using the PCoIP protocol. It stems from improper certificate validation (CWE-295), which may enable an attacker to access remote sessions through a man-in-the-middle attack. The issue affects the Android, Linux, macOS, and Windows native clients for Amazon WorkSpaces, with a CVSS v3.1 base score of 7.5 (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H), indicating high impact but requiring high attack complexity and user interaction.

An attacker with network access can exploit this vulnerability by positioning themselves for a man-in-the-middle interception, potentially without privileges, though it demands user interaction such as connecting through a malicious network or clicking a prompt. Successful exploitation grants high-impact access to remote WorkSpaces sessions, compromising confidentiality, integrity, and availability of the targeted sessions.

AWS has published a security bulletin at https://aws.amazon.com/security/security-bulletins/AWS-2025-001/ detailing the issue. Mitigation involves updating the affected native clients, with release notes available for Android (https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-android-client.html#android-release-notes), Linux (https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-linux-client.html#linux-release-notes), macOS (https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-osx-client.html#osx-release-notes), and Windows (https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-windows-client.html#windows-release-notes).

Details

CWE(s)
CWE-295

References