Container Escape - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
December 16, 2025
Last Seen
December 16, 2025

Container Escape is a MITRE ATT&CK technique describing an attacker breaking out of a compromised container to the host or other containers, enabling higher privileges and broader access.

Overview

Container Escape is a MITRE ATT&CK technique describing an attacker breaking out of a compromised container to the host or other containers, enabling higher privileges and broader access. It leverages container runtime weaknesses, kernel exploits, misconfigurations (e.g., privileged containers, leaked capabilities), and orchestration flaws to evade isolation. Its significance is amplified by the ubiquity of containers in cloud-native deployments, where a successful escape can lead to extensive access across hosts and workloads.

Related Threat Clusters

Recent Intelligence Reports

  • Zero-Days in the Age of AI: Behind the Scenes of ZeroDay.cloud 2025 — Wiz · December 16, 2025

CVSS v3.1 Breakdown