« Volver al listado

Microsoft

Microsoft Azure Kubernetes Service: vulnerabilidades y CVE

Microsoft Azure Kubernetes Service tiene 11 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 6 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE11
Últimos 12 meses4
Críticas6
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-44487Alta (7.5)100%⚠ Explotación activa10 oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-50516Crítica (9.4)0.83%—11 ago 2026
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56163Crítica (10)0.90%—24 jul 2026
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-32193Alta (8.8)0.37%—9 jun 2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.
CVE-2026-33105Crítica (9.8)0.90%—3 abr 2026
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2024-21403Crítica (9)1.3%—13 feb 2024
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
CVE-2024-21376Crítica (9)1.2%—13 feb 2024
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
CVE-2023-44487Alta (7.5)100%⚠ Explotación activa10 oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2023-29332Crítica (9.8)2.7%—12 sept 2023
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVE-2021-27075Media (6.8)1.4%—11 mar 2021
Azure Virtual Machine Information Disclosure Vulnerability
CVE-2021-24109Media (6.8)2.2%—25 feb 2021
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVE-2021-1677Media (5.5)1.1%—12 ene 2021
Azure Active Directory Pod Identity Spoofing Vulnerability

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1078 Valid Accounts3
  3. T1059 Command and Scripting Interpreter1
  4. T1068 Exploitation for Privilege Escalation1
  5. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Microsoft