logo

Exploitation in the Wild of Aviatrix Controller RCE (Campaign)

ID: ba44a512-b404-55a8-9a11-fd99287c5da7

STIX ID: report--ba44a512-b404-55a8-9a11-fd99287c5da7

Feed Name: Wiz Cloud Threat Landscape

Threat Score
78/100

Date Published: 2025-01-11

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers observed active exploitation of Aviatrix Controller RCE (CVE-2024-50603) in the wild: unauthenticated command injection in API parameters has been used to run XMRig cryptocurrency miners and deploy Sliver backdoors on publicly exposed cloud controllers, with exploitation activity increasing after a public proof-of-concept and a Nuclei template were released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.