Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cloud Security

Critical Aviatrix Controller Vulnerability Exploited Against Cloud Environments

Attackers are exploiting a critical vulnerability in Aviatrix Controller to execute arbitrary code in AWS cloud environments.

Fluent Bit cloud attack

Threat actors are exploiting a critical-severity remote code execution (RCE) vulnerability in Aviatrix Controller to deploy malware, cybersecurity firm Wiz reports.

The issue, tracked as CVE-2024-50603 (CVSS score of 10/10), exists because user-supplied input is not properly neutralized, allowing unauthenticated, remote attackers to inject arbitrary code that is executed with high privileges on the Aviatrix cloud networking platform.

The solution is designed to help organizations manage and secure their cloud infrastructure across multiple providers from a single place.

Impacting certain endpoints within the Aviatrix Controller’s API, which is implemented in PHP, the vulnerability was patched in December, but technical information on it was only published last week.

Following public disclosure, however, proof-of-concept (PoC) exploit code was published and a Nuclei template was also released.

Over the weekend, Wiz warned that threat actors started exploiting CVE-2024-50603 against AWS cloud environments, to deploy cryptocurrency miners and backdoors.

Advertisement. Scroll to continue reading.

“Immediately following the publication of the exploit, Wiz Research identified evidence of successful exploitation of this vulnerability across several cloud environments,” the cybersecurity firm notes.

The exposed vulnerable instances were confirmed vulnerable to CVE-2024-50603, suggesting that the attackers quickly adopted the fresh exploit code.

Wiz also warns that, because the Aviatrix Controller is deployed in AWS cloud environments with high privileges, the successful exploitation of the security defect could also lead to lateral movement.

“Based on our data, around 3% of cloud enterprise environments have Aviatrix Controller deployed. However, our data shows that in 65% of such environments, the virtual machine hosting Aviatrix Controller has a lateral movement path to administrative cloud control plane permissions,” Wiz says.

To date, however, the cybersecurity firm has not observed cloud lateral movement attempts following initial access, but it expects that threat actors will abuse the flaw to at least enumerate cloud permissions and to exfiltrate data from the compromised environments.

The bug impacts Aviatrix Controller versions 7.x before 7.1.4191 and 7.2.4996. Organizations are advised to update their instances as soon as possible.

Related: First Android Update of 2025 Patches Critical Code Execution Vulnerabilities

Related: Russian Cyberspies Hacked Building Across Street From Target for Wi-Fi Attack

Related: Critical Vulnerabilities Expose Parking Management System to Hacker Attacks

Related: How Technology Can Think Globally and Act Locally to Inform Global Cyber Policies

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Rapid7 announced that Wael Mohamed will assume the role of Chief Executive Officer, replacing current Chief Executive Officer Corey Thomas, who will become Executive Chairman of the Board.

Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter.

CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.