HomeSecurityAmazon WorkSpaces for Linux: Vulnerability allows credential extraction

Amazon WorkSpaces for Linux: Vulnerability allows credential extraction

Amazon has disclosed a significant security vulnerability in its WorkSpaces client for Linux , which could allow unauthorized users to extract valid credentials authentication and gain unauthorized access to other users' WorkSpaces .

Amazon WorkSpaces for Linux

The vulnerability, tracked as CVE-2025-12779, affects multiple client versions (from 2023.0 to 2024.8) and poses an immediate threat to organizations that rely on Amazon's desktop-as-a-service platform for their remote work infrastructure.

See also: Vulnerability in NVIDIA App for Windows allows code execution

Amazon WorkSpaces: Improper Credential Management

Under certain circumstances, an unauthorized user on the same client machine could extract valid DCV-based authentication credentials for Workspace. This vulnerability bypasses the layer of authentication that separates individual Workspace sessions, potentially exposing sensitive business data and confidential user information to lateral movement attacks.

The credential extraction vulnerability represents a critical oversight in security mechanisms. While WorkSpaces uses multiple layers of security for cloud access, the client-side credential management failed to maintain proper isolation between local users . This means that any user with command-line access or system-level privileges on a shared client machine could retrieve the authentication credentials of other users using the same hardware.

See also: Warning! New vulnerability in Cisco Identity Services Engine (ISE)

Amazon WorkSpaces for Linux: Vulnerability allows credential extraction

The vulnerability targets organizations using DCV-based WorkSpaces with the affected Linux client versions, including enterprises that have deployed WorkSpaces on Linux-based infrastructure or hybrid environments where Linux clients are primary access points.

Amazon has reached out to customers affected by this vulnerability, informing them of the end of support timeline for the affected versions. This communication strategy demonstrates AWS's commitment to addressing the vulnerability. However, organizations with older client installations may face challenges in rapidly remediating their entire user base.

See also: Critical RCE Vulnerability in Anthropic's Claude Desktop

Amazon WorkSpaces for Linux: Vulnerability allows credential extraction

Amazon is resolving CVE-2025-12779 in version 2025.0 of the Amazon WorkSpaces client for Linux (and later versions). Organizations running any version between 2023.0 and 2024.8 should prioritize upgrading immediately. The updated client is available via the Amazon WorkSpaces Client download page.

Security teams should conduct immediate assessments to identify all Linux WorkSpaces clients deployed in their environment. Organizations with multiple client installations in distributed clusters should develop an upgrade strategy to minimize disruption while ensuring timely recovery.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS