logo

Privilege Escalation Issue in Amazon ECS Leads to IAM Hijacking

ID: 01a722ad-cc33-5274-a905-d4ce62b0ff1a

STIX ID: report--01a722ad-cc33-5274-a905-d4ce62b0ff1a

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-08-07

Date Updated: 2026-04-21

Author: Rob Wright

...
...

A researcher presented "ECScape," a technique that forges ACS WebSocket requests to impersonate the ECS agent and trick the ECS control plane into returning IAM task credentials for other containers on the same EC2 host. The proof-of-concept is public, AWS did not assign a CVE or issue a patch and considers customers responsible for hardening EC2-based ECS deployments; recommended mitigations include disabling or restricting IMDS, tightening agent permissions, avoiding co-location of privileged tasks, or using Fargate for stronger isolation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.