CVE-2025-0501
Published: 15 January 2025
Description
An issue in the native clients for Amazon WorkSpaces (when running PCoIP protocol) may allow an attacker to access remote sessions via man-in-the-middle.
Security Summary
CVE-2025-0501 is a vulnerability in the native clients for Amazon WorkSpaces when using the PCoIP protocol. It stems from improper certificate validation (CWE-295), which may enable an attacker to access remote sessions through a man-in-the-middle attack. The issue affects the Android, Linux, macOS, and Windows native clients for Amazon WorkSpaces, with a CVSS v3.1 base score of 7.5 (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H), indicating high impact but requiring high attack complexity and user interaction.
An attacker with network access can exploit this vulnerability by positioning themselves for a man-in-the-middle interception, potentially without privileges, though it demands user interaction such as connecting through a malicious network or clicking a prompt. Successful exploitation grants high-impact access to remote WorkSpaces sessions, compromising confidentiality, integrity, and availability of the targeted sessions.
AWS has published a security bulletin at https://aws.amazon.com/security/security-bulletins/AWS-2025-001/ detailing the issue. Mitigation involves updating the affected native clients, with release notes available for Android (https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-android-client.html#android-release-notes), Linux (https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-linux-client.html#linux-release-notes), macOS (https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-osx-client.html#osx-release-notes), and Windows (https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-windows-client.html#windows-release-notes).
Details
- CWE(s)