Security News > 2023 > October > ShellTorch flaws expose AI servers to code execution attacks
![ShellTorch flaws expose AI servers to code execution attacks](/static/build/img/news/shelltorch-flaws-expose-ai-servers-to-code-execution-attacks-medium.jpg)
The TorchServe flaws discovered by the Oligo Security research team can lead to unauthorized server access and remote code execution on vulnerable instances.
Due to insecure deserialization in the SnakeYAML library, attackers can upload a model with a malicious YAML file to trigger remote code execution.
"Once an attacker can breach an organization's network by executing code on its PyTorch server, they can use it as an initial foothold to move laterally to infrastructure in order to launch even more impactful attacks, especially in cases where proper restrictions or standard controls are not present," explains Oligo.
Amazon has also published a security bulletin about CVE-2023-43654, providing mitigation guidance for customers using Deep Learning Containers in EC2, EKS, or ECS. Finally, Oligo has released a free checker tool that admins can use to check if their instances are vulnerable to ShellTorch attacks.
Arm warns of Mali GPU flaws likely exploited in targeted attacks.
Millions of Exim mail servers exposed to zero-day RCE attacks.
News URL
Related news
- Over 660,000 Rsync servers exposed to code execution attacks (source)
- Apache fixes remote code execution bypass in Tomcat web server (source)
- Apache Tomcat Vulnerability CVE-2024-56337 Exposes Servers to RCE Attacks (source)
- Over 3 million mail servers without encryption exposed to sniffing attacks (source)
- New AI Jailbreak Method 'Bad Likert Judge' Boosts Attack Success Rates by Over 60% (source)
- Preventing the next ransomware attack with help from AI (source)
- Rsync vulnerabilities allow remote code execution on servers, patch quickly! (source)
- Meta's Llama Framework Flaw Exposes AI Systems to Remote Code Execution Risks (source)
- Top 5 AI-Powered Social Engineering Attacks (source)
- Google says hackers abuse Gemini AI to empower their attacks (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-09-28 | CVE-2023-43654 | Unspecified vulnerability in Pytorch Torchserve TorchServe is a tool for serving and scaling PyTorch models in production. | 9.8 |