CVE-2025-0501
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jan 15, 2025
CWE ID 295
Summary
CVE-2025-0501 is a vulnerability affecting Amazon WorkSpaces native clients that utilize the PCoIP protocol. This issue grants man-in-the-middle attackers the ability to gain unauthorized access to remote sessions, potentially leading to data breaches or unauthorized system access. The vulnerability exists within the native clients and can be exploited by intercepting and modifying communication between the client and server. Users are encouraged to install available patches or updates to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.