Amazon WorkSpaces Linux Bug Lets Attackers Steal Credentials
A flaw in Amazon WorkSpaces for Linux lets attackers steal authentication tokens.
A newly disclosed security flaw in Amazon WorkSpaces client for Linux could allow attackers to extract valid authentication tokens and gain unauthorized access to corporate environments.
The vulnerability poses a serious risk to organizations relying on Amazon’s desktop-as-a-service platform for remote operations.
In its advisory , Amazon AWS stated “Under certain circumstances, an unintended user may be able to extract a valid authentication token from the client machine and access another user’s WorkSpace.”
The vulnerability ( CVE-2025-12779 ) affects Amazon WorkSpaces client versions 2023.0 through 2024.8, exposing enterprises that depend on Linux-based or hybrid remote desktop infrastructure.
Improper isolation between local user sessions means that any user with command-line or system-level access on a shared machine could retrieve another user’s authentication credentials.
This vulnerability creates a potential risk of lateral movement using compromised credentials.
The root cause lies in improper token handling. When the Linux client generates and stores DCV-based authentication tokens, it fails to enforce adequate isolation between users on the same host system.
This creates a window where unintended users could extract valid tokens, bypassing session-level authentication safeguards.
While Amazon WorkSpaces includes multiple cloud-side security layers, this client-side oversight represents a credential management failure.
In shared or multi-user systems — common in development and testing environments — an attacker could potentially impersonate another user, accessing sensitive data or business applications tied to that account.
The vulnerability has a CVSS score of 8.8 and was resolved in the Amazon WorkSpaces client for Linux version 2025.0 and later.
There is currently no evidence of active exploitation in the wild, but the ease of local access may make proof-of-concept (PoC) exploits likely in the near future.
To limit exposure to CVE-2025-12779 and protect Amazon WorkSpaces environments, organizations should take the following actions:
This vulnerability highlights a theme in enterprise security: even robust cloud infrastructure can be undermined by weak points on the client side.
The flaw underscores the importance of defense-in-depth, where both cloud and endpoint layers enforce strong authentication, encryption, and session isolation.
It also reinforces the need for automated update pipelines that can push patches rapidly across distributed systems without manual intervention.
As organizations address these client-side risks, adopting broader cloud security best practices becomes essential to building true cyber resilience.
Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.
Researchers found nine NuGet packages hiding time-delayed code that can crash apps or corrupt industrial systems.
The ClickFix malware now uses videos, timers, and OS-specific tricks to deceive users into infecting their own devices.
Cybercriminals are exploiting hotel booking platforms in a global phishing scheme that tricks guests into paying for reservations twice.
Cisco warns that hackers are actively exploiting a 0-day flaw in its firewall software, putting unpatched systems at risk of full compromise.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
