Impact
The Amazon Athena ODBC driver, in versions before 2.1.0.0, allocates resources during parsing without any limits. An actor who can influence the data that the driver parses may supply crafted input that triggers uncontrolled consumption of resources, potentially exhausting the driver’s available capacity and causing a denial of service to an application that relies on the driver.
Affected Systems
Amazon’s Athena ODBC driver on Linux, macOS (Intel and arm), and Windows is affected. All installations of the driver version older than 2.1.0.0 are vulnerable, regardless of the underlying operating system.
Risk and Exploitability
The CVSS score of 8.7 classifies the vulnerability as high severity. The EPSS score of less than 1% indicates a low probability of exploitation in the near term, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Based on the description, the likely attack vector involves delivering crafted input that the driver will parse to trigger excessive resource consumption; this inference is derived from the need to supply such input to exploit the flaw.
OpenCVE Enrichment