Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-32193

Опубликовано: 09 июн. 2026
Источник: msrc
CVSS3: 8.8
EPSS Низкий

Описание

Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.

FAQ

How could an attacker exploit this vulnerability?

An attacker who can run an untrusted container configured with hostNetwork could send specially crafted requests to a host‑level service that was not intended for unauthenticated access. This could allow the attacker to break out of the container and gain control of the AKS worker node.

According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?

An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.

Обновления

ПродуктСтатьяОбновление
Azure Kubernetes Service

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Unlikely

EPSS

Процентиль: 26%
0.00336
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 месяцев назад

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.

CVSS3: 8.8
github
около 2 месяцев назад

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.

CVSS3: 8.8
fstec
около 2 месяцев назад

Уязвимость служба для развертывания контейнерных приложений и управления ими Azure Kubernetes Service (AKS), связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 26%
0.00336
Низкий

8.8 High

CVSS3