---
cve: "CVE-2025-0500"
severity: "HIGH"
cvss: 7.7
epss: "0.5%"
vendor: "Amazon"
kev: false
exploited: false
published: "2025-01-15 19:15:27"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-23T16:39:09+02:00"
---

# CVE-2025-0500

> 7.7 HIGH

## Beschreibung

An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |

## Referenzen

- <https://aws.amazon.com/security/security-bulletins/AWS-2025-001/>
- <https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-windows-client.html#windows-release-notes>
- <https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-osx-client.html#osx-release-notes>
- <https://docs.aws.amazon.com/workspaces/latest/userguide/amazon-workspaces-linux-client.html#linux-release-notes>
- <https://docs.aws.amazon.com/appstream2/latest/developerguide/client-release-versions.html>
- <https://docs.aws.amazon.com/dcv/latest/adminguide/doc-history-release-notes.html#dcv-2023-1-16388jul>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-0500) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
