VDB

CVE-2025-0500

CVE-2025-0500 PUBLISHED CVSS 7.699999809265137 HIGH

An issue in the native clients for Amazon WorkSpaces, Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle.

EPSS 0.29% · 52.7th percentile

Risk Scores

CVSS 4.0
7.699999809265137
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.29%
52.7th percentile

Affected Products

VendorProductVersions
AmazonWorkSpaces Client5.0.0, 2023.0, 5.5.0
AmazonDCV Client0, 2020.2.7459, 2020.2.2078
AmazonAppStream 2.0 Client1.1.1025

Timeline

  • Jan 15, 2025 CVE ID Reserved
  • Jan 15, 2025 CVE Published
  • Jan 15, 2025 PoC Published
  • Jan 15, 2025 PoC Published
  • Jan 16, 2025 EPSS Score
  • Jan 16, 2025 PoC Published
  • Jan 16, 2025 PoC Published
  • Jan 22, 2025 PoC Published
  • Jan 31, 2025 EPSS Score
  • Feb 9, 2025 Coalition ESS Score
  • Feb 16, 2025 EPSS Score
  • Mar 3, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›