Palo Alto Networks Unit 42 disclosed FabricScape, an attack technique tied to CVE-2022-30137 that allows an attacker to escape a Microsoft Service Fabric environment and compromise the broader cluster. The issue affects the boundary between hosted workloads and the underlying Service Fabric infrastructure, enabling a malicious actor with code execution in a service container or application context to move beyond the intended isolation model.
Successful exploitation can let an attacker take over cluster resources, interfere with other applications, and gain high-privilege control over the Service Fabric environment. The finding highlights a serious risk for organizations using Service Fabric to host multi-tenant or business-critical services, because a breach of one workload can be leveraged into compromise of the entire cluster if the vulnerability is not remediated.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 published research detailing 'FabricScape,' explaining how CVE-2022-30137 could be used to escape Service Fabric and take over a cluster. The publication provided technical details that expanded public understanding of the vulnerability's impact.
Microsoft addressed CVE-2022-30137, a vulnerability in Azure Service Fabric that could allow an attacker to escape a containerized application and gain control of the Service Fabric cluster. The Unit 42 report discusses the issue as a disclosed and patched flaw.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.