CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2025-12815: An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on…

CVE-2025-12815. CVSS 3.1 base score 4.3 (MEDIUM, Source advisory). EPSS 0.00291 (percentile 0.19762), scored 2026-10-06.

Affected technology

An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS · before version 2025.09 may
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

An authenticated remote user may view another user's active desktop session metadata, including periodical desktop preview screenshots. Source advisory’s CVSS 4.0 assessment (base score 5.3/10) rates confidentiality, integrity and availability impact as none.

Published

CWE
CWE-283
CCR priority
17.3 /100 (P5)
CVSS 3.1
4.3 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N · Source advisory
EPSS
0.00291 · percentile 0.19762 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-12815.html