Possible exploit variant for CVE-2024-9042 (Kubernetes OS Command Injection), (Wed, Dec 10th)
ID: 294c7582-44fe-5f60-bf8a-3af4bc3fa617
STIX ID: report--294c7582-44fe-5f60-bf8a-3af4bc3fa617
Feed Name: SANS ISC Diary
The report summarizes a command-injection vulnerability in Kubernetes NodeLogQuery (CVE-2024-9042) that can lead to remote command execution on Windows nodes when the logs-query feature is enabled and an attacker has log-read permissions. The author observed recent honeypot traffic using '$(...)' command-injection patterns — this time with payloads placed in the request path — suggesting active probing or exploitation attempts; however, exploitation is constrained by specific environmental conditions, so monitoring and targeted mitigations are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
