CVE-2025-0500: Amazon Appstream 2.0 Client

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle.

Affected products

  • Amazon Appstream 2.0 Client: from 1.1.1025, before 1.1.1332 (fixed in 1.1.1332)
  • Amazon Dcv Client: before 2023.1.6703 (fixed in 2023.1.6703); from 2020.2.7459, before 2023.1.9127 (fixed in 2023.1.9127); from 2020.2.2078, before 2023.1.6703 (fixed in 2023.1.6703)
  • Amazon Workspaces Client: from 5.0.0, before 5.21.0 (fixed in 5.21.0); from 2023.0, before 2024.2 (fixed in 2024.2); from 5.5.0, before 5.21.0 (fixed in 5.21.0)

Published 2025-01-15. Last modified 2026-06-17.