CVE-2025-14764 describes a missing cryptographic key commitment in the Amazon S3 Encryption Client for Go, specifically impacting scenarios where encrypted data keys are stored in an "instruction file." This vulnerability allows an attacker with write access to an S3 bucket to introduce a new encrypted data key that decrypts to different plaintext. The vulnerability has a CVSS score of 5.3 (Medium), indicating a network-based attack with high complexity, requiring low privileges, and resulting in a high integrity impact (data manipulation). There is no confidentiality or availability impact. Currently, there is no known active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. While there is minimal community discussion and media coverage, the issue has been acknowledged by AWS.
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.