"WireServing" Up Credentials: Escalating Privileges in Azure Kubernetes Services
ID: 5b95bcc8-61c1-52ac-8000-5493b6c19d56
STIX ID: report--5b95bcc8-61c1-52ac-8000-5493b6c19d56
Feed Name: Google Cloud Threat Intelligence
Threat Score
Mandiant disclosed a privilege-escalation vulnerability in Azure Kubernetes Service (AKS) clusters configured with Azure CNI and Azure Network Policy that allowed an attacker with Pod-level code execution to access the Azure WireServer/HostGAPlugin, recover TLS bootstrap tokens, and perform a TLS bootstrap attack to obtain cluster secrets; Microsoft has been notified and fixed the underlying issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
