HomeSecurityAmazon EKS vulnerabilities expose AWS credentials

Amazon EKS vulnerabilities expose AWS credentials

Critical vulnerabilities in Amazon Elastic Kubernetes Service (EKS) allow containers with excessive privileges to expose sensitive AWS credentials through packet sniffing and API spoofing.

See also: Amazon: AI will lead to staff reductions

Amazon EKS vulnerabilities

The research , published on June 19, 2025, demonstrates how misconfiguration of containers can facilitate unauthorized access and privilege escalation in cloud environments , highlighting serious risks to AWS’s shared responsibility model. The vulnerability specifically targets the Amazon EKS Pod Identity feature , which is designed to simplify AWS credential management for pods running on EKS clusters. The service operates through the eks-pod-identity-agent plugin , which runs as a DaemonSet in the kube-system namespace and exposes an API at the link-local address 169.254.170.23 for IPv4 and [fd00:ec2::23] for IPv6, on port 80.

The agent accepts Kubernetes service account tokens in the Authorization and calls the eks-auth:AssumeRoleForPodIdentity.

When applications make requests to AWS services, the SDK automatically retrieves temporary credentials from the EKS Pod Identity agent, which in turn interacts with the AWS API to obtain the necessary credentials corresponding to the relevant IAM role.

Researchers identified two main attack methods that exploit the excessive privileges of containers.

See also: Amazon data centers: Significant investments in Australia

The first concerns packet sniffing, in which containers configured with the hostNetwork: true can monitor network traffic and intercept credentials transmitted in plaintext from the API endpoint 169.254.170.23:80.

Amazon EKS vulnerabilities expose AWS credentials
Amazon EKS vulnerabilities expose AWS credentials

A proof-of-concept using the tcpdumpsuccessfully demonstrated theft via unencrypted HTTP traffic.

The second attack method relies on API spoofing. Even when the CAP_NET_RAW, containers that retain the CAP_NET_ADMIN can modify the network interface card (NIC) settings.

Attackers can disable the eks-pod-identity-agent by deleting the link-local address, and then deploy their own HTTP server at 169.254.170.23:80, aiming to intercept tokens sent via the Authorization.

Trend Micro developed a proof-of-concept in Python, using the pyroute2, to demonstrate the functionality of this attack.

See also: Amazon: Humanoid robots for package delivery?

Based on the above, it becomes clear that poor privilege management and inadequate isolation in cloud-native environments, such as Amazon EKS, can lead to serious security breaches. These vulnerabilities highlight a fundamental problem: the need for a stricter least privilege model in assigning capabilities to containers and better isolation between pods.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS