VDB
CVE-2025-0501
CVE-2025-0501
PUBLISHED
CVSS 7.699999809265137 HIGH
An issue in the native clients for Amazon WorkSpaces Clients when running PCoIP protocol may allow an attacker to access remote sessions via man-in-the-middle.
EPSS 0.21% · 42.6th percentile
Risk Scores
CVSS 4.0
7.699999809265137
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.21%
42.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amazon | WorkSpaces Client | 3.0.0, 3.0.0, 3.0.1 |
Exploit Intelligence
- CIRCL seen: CVE-2025-0501 (circl-sighting)
- CIRCL seen: CVE-2025-0501 (circl-sighting)
- CIRCL seen: CVE-2025-0501 (circl-sighting)
- CIRCL seen: CVE-2025-0501 (circl-sighting)
- CIRCL seen: CVE-2025-0501 (circl-sighting)
- https://aws.amazon.com/security/security-bulletins/AWS-2025-001/ (circl)
- https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-windows-client.html#windows-release-notes (circl)
- https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-osx-client.html#osx-release-notes (circl)
- https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-linux-client.html#linux-release-notes (circl)
- https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-android-client.html#android-release-notes (circl)
Timeline
- Jan 15, 2025 CVE ID Reserved
- Jan 15, 2025 CVE Published
- Jan 15, 2025 PoC Published
- Jan 15, 2025 PoC Published
- Jan 16, 2025 EPSS Score
- Jan 16, 2025 PoC Published
- Jan 16, 2025 PoC Published
- Jan 22, 2025 PoC Published
- Jan 31, 2025 EPSS Score
- Feb 9, 2025 Coalition ESS Score
- Feb 16, 2025 EPSS Score
- Mar 3, 2025 EPSS Score
References
- https://aws.amazon.com/security/security-bulletins/AWS-2025-001/ vendor-advisory
- https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-windows-client.html#windows-release-notes patch
- https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-osx-client.html#osx-release-notes patch
- https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-linux-client.html#linux-release-notes patch
- https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-android-client.html#android-release-notes patch
- https://nvd.nist.gov/vuln/detail/CVE-2025-0501 advisory
- https://aws.amazon.com/security/security-bulletins/AWS-2025-001 url