CVE-2025-12779

Published Nov 5, 2025

Last updated 3 months ago

Overview

Description
Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authentication token for DCV-based WorkSpaces to other local users on the same client machine. Under certain circumstances, a local user may be able to extract another local user's authentication token from the shared client machine and access their WorkSpace. To mitigate this issue, users should upgrade to the Amazon WorkSpaces client for Linux version 2025.0 or later.
Source
ff89ba41-3aa1-4d27-914a-91399e9639e5
NVD status
Deferred

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.8
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
6
Exploitability score
2
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity
HIGH

Weaknesses

ff89ba41-3aa1-4d27-914a-91399e9639e5
CWE-497

Social media

Hype score
Not currently trending
  1. #VulnerabilityReport #AuthenticationToken Amazon Fixes High-Severity Authentication Token Exposure in WorkSpaces Client for Linux (CVE-2025-12779) https://t.co/3nrwLMqjOO

    @Komodosec

    14 Dec 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Amazon WorkSpaces for Linuxに認証トークン露出の高深刻度の脆弱性(CVE-2025-12779) https://t.co/kkmSzoFYMm #セキュリティ対策Lab #セキュリティ #Security

    @securityLab_jp

    13 Nov 2025

    68 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ⚠️Vulnerabilidad en productos Amazon ❗CVE-2025-12779 ➡️Más info: https://t.co/O1m8kAqBqF https://t.co/mEz2aToMgA

    @CERTpy

    11 Nov 2025

    97 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Amazon Fixes High-Severity Authentication Token Exposure in WorkSpaces Client for Linux (CVE-2025-12779) https://t.co/6WhIrbfnVx

    @Karma_X_Inc

    8 Nov 2025

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. That Linux "WorkSpace" Is a Backdoor to Your AWS Cloud. (A Non-Technical Risk Brief on the CVE-2025-12779 Flaw). READ the full report on - https://t.co/9vI82PbDkU https://t.co/Im5WR1N0vc

    @cyberbivash

    7 Nov 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. How to Detect and Hunt the AWS WorkSpaces "Auth Token" Flaw (IOCs for CVE-2025-12779). Read the full report on - https://t.co/6J1r8i6O6a https://t.co/t6opLLgIY8

    @cyberbivash

    7 Nov 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. How to Detect and Hunt the AWS WorkSpaces "Auth Token" Flaw (IOCs for CVE-2025-12779). Read the full report on - https://t.co/6J1r8i6O6a https://t.co/cN7bYk9jXF

    @cyberbivash

    7 Nov 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. [CVE-2025-12779: HIGH] Security alert: Ensure cyber safety! Amazon WorkSpaces client for Linux 2023.0-2024.8 has token vulnerability. Upgrade to version 2025.0+ to stay protected from local users accessing y...#cve,CVE-2025-12779,#cybersecurity https://t.co/GOZr93szTC https://t.c

    @CveFindCom

    5 Nov 2025

    102 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2025-12779 Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authentication token for DCV-b… https://t.co/WBZ2Kdv0IS

    @CVEnew

    5 Nov 2025

    375 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes