THN 8.8 HIGH

Researchers Uncover ECScape Flaw in Amazon ECS Enabling Cross-Task Credential Theft

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

...

AI Analysis

A vulnerability in Amazon ECS allows a low-privileged container to escalate privileges by stealing credentials from higher-privileged tasks on the same EC2 instance. This can lead to lateral movement, data access, and environment control. The flaw exploits an undocumented ECS internal protocol, enabling credential theft and impersonation. Mitigations include using AWS Fargate and restricting metadata service access.

Visit Original Source

Basic Information

ID THN:DA3AF2B3E32753AE84E55948CC666705
Published Aug 6, 2025 at 20:30

AI Assessment

AI Severity High
Vendor Amazon
Product Amazon ECS
Version Unknown

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.