Executive brief
Amazon WorkSpaces is a managed desktop service that allows users to access cloud-based virtual desktops. A security flaw in the Linux version of the client software could allow a person with access to the same physical or virtual machine to steal a user's login token. If successful, an unauthorized individual could use that token to hijack the victim's virtual desktop session and access their files and applications.
Technical details
An improper authentication token handling vulnerability exists in the Amazon WorkSpaces client for Linux (versions 2023.0 through 2024.8). The flaw allows a local attacker on the same client machine to extract valid authentication tokens for DCV-based WorkSpaces. This occurs because the token is exposed in a manner accessible to other local processes or users. An attacker with local access can leverage this token to gain unauthorized access to the victim's remote WorkSpace session. The issue is resolved in version 2025.0.
Affected products
- Amazon WorkSpaces client for Linux 2023.0 through 2024.8
Timeline
- 2025-11-05: disclosed
- 2025-11-05: patched: Fixed in version 2025.0