VYPR
Medium severity4.3OSV Advisory· Published Nov 6, 2025· Updated Apr 15, 2026

CVE-2025-12815

CVE-2025-12815

Description

An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.09 may allow an authenticated remote user to view another user's active desktop session metadata, including periodical desktop preview screenshots.

To mitigate this issue, users should upgrade to version 2025.09 or above.

Affected products

1
  • Aws/ResOSV
    Range: 2023.11, 2024.01, 2024.01.01, …

Patches

1
ef28c6a884d9

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

3

News mentions

0

No linked articles in our index yet.