CVE-2025-0501 describes a high-severity vulnerability (CVSS 7.5) in Amazon WorkSpaces native clients utilizing the PCoIP protocol. An attacker could exploit this flaw through a man-in-the-middle attack, potentially gaining full access to remote sessions. The attack requires high complexity and user interaction, but could lead to complete compromise of confidentiality, integrity, and availability. Currently, there is no public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Amazon | WorkSpaces Client | >= 3.0.1, < 5.0.1CNA affecteddefault unaffected | |
| Amazon | WorkSpaces Client | >= 3.0.0, < 2024.6CNA affecteddefault unaffected | |
| Amazon | WorkSpaces Client | >= 3.0.0, < 5.22.1CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.