Ownership Verification Flaw in AWS Research and Engineering Studio
CVE-2025-12815

5.3MEDIUM

Key Information:

Vendor

Aws

Vendor
CVE Published:
6 November 2025

What is CVE-2025-12815?

An ownership verification issue exists in the Virtual Desktop preview page of the Research and Engineering Studio on AWS versions before 2025.09. This flaw can allow authenticated remote users to gain unauthorized access to another user's active desktop session metadata, which includes periodic desktop preview screenshots. To protect sensitive information, it is critical for users to upgrade to version 2025.09 or later.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Research and Engineering Studio (RES) 2025.09

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.