CVE-2025-0501: Amazon Workspaces Client
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue in the native clients for Amazon WorkSpaces (when running PCoIP protocol) may allow an attacker to access remote sessions via man-in-the-middle.
Affected products
- Amazon Workspaces Client: from 3.0.0, before 5.22.1 (fixed in 5.22.1); from 3.0.0, before 2024.6 (fixed in 2024.6); from 3.0.1, before 5.0.1 (fixed in 5.0.1)
Published 2025-01-15. Last modified 2026-06-17.