Executive brief
Research and Engineering Studio on AWS (RES) is a web portal used by administrators to manage secure cloud-based research environments. A security flaw was found where an authorized user could view screenshots and metadata of other users' active virtual desktop sessions. This could lead to the unauthorized exposure of sensitive research data or intellectual property being displayed on a colleague's screen.
Technical details
An ownership verification vulnerability exists in the Virtual Desktop preview page of Research and Engineering Studio (RES) on AWS. The flaw allows an authenticated remote user to bypass access controls and view metadata and periodic desktop screenshots of active sessions belonging to other users. This is caused by insufficient validation of session ownership when requesting preview data. The issue is resolved in RES version 2025.09, which implements proper ownership checks.
Affected products
- AWS Research and Engineering Studio (RES) on AWS < 2025.09
Timeline
- 2025-11-06: disclosed
- 2025-11-06: patched: Fixed in version 2025.09