Junglewise Threat Intelligence

CVE-2025-12815: AWS Research and Engineering Studio ownership verification bypass in Virtual Desktop preview

CVE-2025-12815 · Severity: high · Published 2025-11-06

Technologies: Amazon Web Services Research and Engineering Studio, Amazon AWS. Vendors: AWS, Amazon Web Services, Amazon.

Executive brief

Research and Engineering Studio on AWS (RES) is a web portal used by administrators to manage secure cloud-based research environments. A security flaw was found where an authorized user could view screenshots and metadata of other users' active virtual desktop sessions. This could lead to the unauthorized exposure of sensitive research data or intellectual property being displayed on a colleague's screen.

Technical details

An ownership verification vulnerability exists in the Virtual Desktop preview page of Research and Engineering Studio (RES) on AWS. The flaw allows an authenticated remote user to bypass access controls and view metadata and periodic desktop screenshots of active sessions belonging to other users. This is caused by insufficient validation of session ownership when requesting preview data. The issue is resolved in RES version 2025.09, which implements proper ownership checks.

Affected products

  • AWS Research and Engineering Studio (RES) on AWS < 2025.09

Timeline

  • 2025-11-06: disclosed
  • 2025-11-06: patched: Fixed in version 2025.09

References

Related threats