Microsoft
Microsoft Azure Kubernetes Service: vulnerabilidades y CVE
Microsoft Azure Kubernetes Service tiene 11 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 6 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses4
Críticas6
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-50516 | Crítica (9.4) | 0.83% | — | 11 ago 2026 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-56163 | Crítica (10) | 0.90% | — | 24 jul 2026 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-32193 | Alta (8.8) | 0.37% | — | 9 jun 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally. |
| CVE-2026-33105 | Crítica (9.8) | 0.90% | — | 3 abr 2026 | Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2024-21403 | Crítica (9) | 1.3% | — | 13 feb 2024 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability |
| CVE-2024-21376 | Crítica (9) | 1.2% | — | 13 feb 2024 | Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability |
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2023-29332 | Crítica (9.8) | 2.7% | — | 12 sept 2023 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability |
| CVE-2021-27075 | Media (6.8) | 1.4% | — | 11 mar 2021 | Azure Virtual Machine Information Disclosure Vulnerability |
| CVE-2021-24109 | Media (6.8) | 2.2% | — | 25 feb 2021 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability |
| CVE-2021-1677 | Media (5.5) | 1.1% | — | 12 ene 2021 | Azure Active Directory Pod Identity Spoofing Vulnerability |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.