Spoofing attack in AWS SDK for PHP - CVE-2025-14761

 

Spoofing attack in AWS SDK for PHP - CVE-2025-14761

Published: December 18, 2025


Vulnerability identifier: #VU120184
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-14761
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to a single ciphertext can be decrypted into 2 different plaintexts by using different encryption keys. A remote user with permission to upload a new instruction file to the S3 bucket to replace the existing instruction file can create a rouge EDK key and force the application to use it in any future attempts to decrypt the underlying encrypted message with the S3EC.


Affected software

AWS SDK for PHP
Moodle
Amazon AWS SDK
AWS SDK for PHP
Amazon Web Services (AWS) Toolbox

How to mitigate CVE-2025-14761

Install updates from vendor's website.

AWS SDK for PHP - update to 3.368.0
AWS SDK for PHP - update to 3.368.0
Moodle - addressed in versions 4.5.11, 5.0.7, 5.1.4
Amazon Web Services (AWS) Toolbox - addressed in versions 11.0.4, 12.0.2

External References

Related Security Bulletins