Skip to content
Amazon WorkSpaces Linux Flaw Allows Credential Theft

Amazon WorkSpaces Linux Flaw Allows Credential Theft

First seen 2 Dec 2025, 18:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A security flaw in the Amazon WorkSpaces client for Linux, identified as CVE-2025-12779, enables local attackers to extract valid authentication tokens, granting unauthorized access to other users' WorkSpace sessions. Organizations utilizing AWS's virtual desktop infrastructure are affected by this vulnerability. AWS issued a security bulletin on November 5, 2025, detailing the issue and recommending immediate remediation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track ClickFix, Amazon and CVE-2025-12779 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed