CVE-2025-0500
EUVD-2025-172015.01.2025, 19:15
An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| amazon | workspaces | 5.0.0 ≤ 𝑥 < 5.21.0 | CNA |
| amazon | workspaces | 2023.0 ≤ 𝑥 < 2024.2 | CNA |
| amazon | workspaces | 1.1.1025 ≤ 𝑥 < 1.1.1332 | CNA |
| amazon | workspaces | 𝑥 < 2023.1.6703 | CNA |
| amazon | workspaces | 2020.2.7459 ≤ 𝑥 < 2023.1.9127 | CNA |
| amazon | workspaces | 5.5.0 ≤ 𝑥 < 5.21.0 | CNA |
| amazon | workspaces | 2020.2.2078 ≤ 𝑥 < 2023.1.6703 | CNA |
Common Weakness Enumeration