Impact
A flaw in the Base64 decoder of Amazon aws‑sdk‑cpp allows an out‑of‑bounds write which can overwrite adjacent heap memory. The defect can trigger a crash or result in heap memory corruption. The vulnerability is classified as CWE‑787 and permits a remote authenticated user to supply crafted Base64 data that will be processed by any application linked to the affected SDK.
Affected Systems
AWS aws‑sdk‑cpp before version 1.11.862 is affected. Updating to 1.11.862 or newer removes the vulnerability.
Risk and Exploitability
The CVSS score of 6 indicates a medium severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated to an application that uses the vulnerable SDK and to supply malicious Base64 input, so the attack vector is remote authenticated. The lack of public exploits suggests it is not yet widely abused, but the risk of heap corruption remains significant.
OpenCVE Enrichment