From Container to Cluster: Chained Escape Attacks in Kubernetes and Orchestration Platforms

Jia-Ning Luo, Wen-Han Zou, Shih-Wei Huang · IEEE Access · 2025

Container virtualization offers a lightweight and agile alternative to traditional virtual machines, yet its reliance on a shared host kernel creates a fundamentally weaker isolation boundary. This architectural choice exposes systems to container escape attack, a threat that has been extensively studied through the lens of single-vector exploits, such as those leveraging the eBPF subsystem. However, a singular focus on individual exploits fails to capture the full lifecycle of a cluster compromise. This paper addresses this limitation by proposing a chained attack model, a more holistic framework that illustrates how adversaries strategically sequence disparate vulnerabilities to achieve a cascading compromise. Our research demonstrates that an initial escape is merely the first stage of a broader campaign. Subsequent lateral movement and privilege escalation are achieved by exploiting systemic misconfigurations within the container orchestration environment, such as improperly scoped service account tokens or insecurely shared persistent volumes. This study underscores the inadequacy of single-point defenses and highlights the necessity of a multi-layered security posture. We present concrete recommendations to mitigate these chained threats, thereby enhancing the resilience of Kubernetes and other container orchestration platforms.

Read the paper · More papers on PaperTik