Ownership Verification Flaw in AWS Research and Engineering Studio
CVE-2025-12815
5.3MEDIUM
Key Information:
- Vendor
Aws
- Vendor
- CVE Published:
- 6 November 2025
What is CVE-2025-12815?
An ownership verification issue exists in the Virtual Desktop preview page of the Research and Engineering Studio on AWS versions before 2025.09. This flaw can allow authenticated remote users to gain unauthorized access to another user's active desktop session metadata, which includes periodic desktop preview screenshots. To protect sensitive information, it is critical for users to upgrade to version 2025.09 or later.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Research and Engineering Studio (RES) 2025.09
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
