logo

"WireServing" Up Credentials: Escalating Privileges in Azure Kubernetes Services

ID: 5b95bcc8-61c1-52ac-8000-5493b6c19d56

STIX ID: report--5b95bcc8-61c1-52ac-8000-5493b6c19d56

Feed Name: Google Cloud Threat Intelligence

Threat Score
75/100

Date Published: 2024-08-19

Date Updated: 2026-04-27

Author: Mandiant

...
...

Mandiant disclosed a privilege-escalation vulnerability in Azure Kubernetes Service (AKS) clusters configured with Azure CNI and Azure Network Policy that allowed an attacker with Pod-level code execution to access the Azure WireServer/HostGAPlugin, recover TLS bootstrap tokens, and perform a TLS bootstrap attack to obtain cluster secrets; Microsoft has been notified and fixed the underlying issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.