logo

Cloud Attackers Exploit Max-Critical Aviatrix RCE Flaw

ID: 9d82eaf8-c38c-5be9-8268-433ecb590d50

STIX ID: report--9d82eaf8-c38c-5be9-8268-433ecb590d50

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-01-13

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Multiple threat actors are actively exploiting CVE-2024-50603, a maximum-severity (CVSS 10) unauthenticated RCE in Aviatrix Controller, to deploy XMRig cryptomining malware and the Sliver backdoor; proof-of-concept code and automated scanners have driven opportunistic attacks across cloud environments, and Aviatrix has released patches and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.