An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.09 may allow an authenticated remote user to view another user's active desktop session metadata, including periodical desktop preview screenshots.
To mitigate this issue, users should upgrade to version 2025.09 or above.
Metrics
Affected Vendors & Products
References
History
Thu, 06 Nov 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aws
Aws research And Engineering Studio |
|
| Vendors & Products |
Aws
Aws research And Engineering Studio |
Thu, 06 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Nov 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 06 Nov 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.09 may allow an authenticated remote user to view another user's active desktop session metadata, including periodical desktop preview screenshots. To mitigate this issue, users should upgrade to version 2025.09 or above. | |
| Weaknesses | CWE-283 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published: 2025-11-06T17:10:34.559Z
Updated: 2025-11-06T17:40:11.560Z
Reserved: 2025-11-06T16:58:30.192Z
Link: CVE-2025-12815
Updated: 2025-11-06T17:25:52.852Z
Status : Awaiting Analysis
Published: 2025-11-06T18:15:39.700
Modified: 2025-11-06T19:45:09.883
Link: CVE-2025-12815
No data.