- Description
- Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authentication token for DCV-based WorkSpaces to other local users on the same client machine. Under certain circumstances, a local user may be able to extract another local user's authentication token from the shared client machine and access their WorkSpace. To mitigate this issue, users should upgrade to the Amazon WorkSpaces client for Linux version 2025.0 or later.
- Source
- ff89ba41-3aa1-4d27-914a-91399e9639e5
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 8.8
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 6
- Exploitability score
- 2
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity
- HIGH
- ff89ba41-3aa1-4d27-914a-91399e9639e5
- CWE-497
- Hype score
- Not currently trending
#VulnerabilityReport #AuthenticationToken Amazon Fixes High-Severity Authentication Token Exposure in WorkSpaces Client for Linux (CVE-2025-12779) https://t.co/3nrwLMqjOO
@Komodosec
14 Dec 2025
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Amazon WorkSpaces for Linuxに認証トークン露出の高深刻度の脆弱性(CVE-2025-12779) https://t.co/kkmSzoFYMm #セキュリティ対策Lab #セキュリティ #Security
@securityLab_jp
13 Nov 2025
68 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️Vulnerabilidad en productos Amazon ❗CVE-2025-12779 ➡️Más info: https://t.co/O1m8kAqBqF https://t.co/mEz2aToMgA
@CERTpy
11 Nov 2025
97 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Amazon Fixes High-Severity Authentication Token Exposure in WorkSpaces Client for Linux (CVE-2025-12779) https://t.co/6WhIrbfnVx
@Karma_X_Inc
8 Nov 2025
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
That Linux "WorkSpace" Is a Backdoor to Your AWS Cloud. (A Non-Technical Risk Brief on the CVE-2025-12779 Flaw). READ the full report on - https://t.co/9vI82PbDkU https://t.co/Im5WR1N0vc
@cyberbivash
7 Nov 2025
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
How to Detect and Hunt the AWS WorkSpaces "Auth Token" Flaw (IOCs for CVE-2025-12779). Read the full report on - https://t.co/6J1r8i6O6a https://t.co/t6opLLgIY8
@cyberbivash
7 Nov 2025
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
How to Detect and Hunt the AWS WorkSpaces "Auth Token" Flaw (IOCs for CVE-2025-12779). Read the full report on - https://t.co/6J1r8i6O6a https://t.co/cN7bYk9jXF
@cyberbivash
7 Nov 2025
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-12779: HIGH] Security alert: Ensure cyber safety! Amazon WorkSpaces client for Linux 2023.0-2024.8 has token vulnerability. Upgrade to version 2025.0+ to stay protected from local users accessing y...#cve,CVE-2025-12779,#cybersecurity https://t.co/GOZr93szTC https://t.c
@CveFindCom
5 Nov 2025
102 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-12779 Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authentication token for DCV-b… https://t.co/WBZ2Kdv0IS
@CVEnew
5 Nov 2025
375 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes