Amazon WorkSpaces Linux Flaw Allows Credential Theft

Amazon WorkSpaces Linux Flaw Allows Credential Theft

First seen 2 Dec 2025, 18:33 UTC ThecyberexpressEsecurityplanet 21.0

Article Content

Browse articles
ThreatCluster

A security flaw in the Amazon WorkSpaces client for Linux, identified as CVE-2025-12779, enables local attackers to extract valid authentication tokens, granting unauthorized access to other users' WorkSpace sessions. Organizations utilizing AWS's virtual desktop infrastructure are affected by this vulnerability. AWS issued a security bulletin on November 5, 2025, detailing the issue and recommending immediate remediation.