PT-2025-51881 · Amazon Web Services · Aws Sdk For C++

Normj

·

Published

2025-12-17

·

Updated

2025-12-21

·

CVE-2025-14760

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions AWS SDK for C++ versions prior to 1.11.712
Description A missing cryptographic key commitment in the AWS SDK for C++ could allow a user with write access to an S3 bucket to introduce a new encryption data key (EDK) that decrypts to different plaintext. This is possible when the encrypted data key is stored in an instruction file instead of S3’s metadata record.
Recommendations Upgrade AWS SDK for C++ to version 1.11.712 or later.

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2025-14760
GHSA-792F-R46X-R7GM

Affected Products

Aws Sdk For C++