• News/
  • https://www.bleepingcomputer.com/news/security/whoami-attacks-give-hackers-code-execution-on-amazon-ec2-instances/

whoAMI attacks give hackers code execution on Amazon EC2 instances

BleepingComputer
·
Bill Toulas
·
Published Feb 13, 2025
·
Updated

Security researchers discovered a name confusion attack that allows access to an Amazon Web Services account to anyone that publishes an Amazon Machine Image (AMI) with a specific name. Dubbed "whoAMI," the attack was crafted by DataDog researchers in August 2024, who demonstrated that it's possible for attackers to gain code execution within AWS accounts by exploiting how software projects retrieve AMI IDs. Amazon confirmed the vulnerability and pushed a fix in September but the problem persists on the customer side in environments where organizations fail to update the code. AMIs are virtual machines preconfigured with the necessary software (operating system, applications) used for creating virtual servers, which are called EC2 (Elastic Compute Cloud) instances in the AWS ecosystem. There are public and private AMIs, each with a specific identifier. In the case of public ones, users can search in the AWS catalog for the right ID of the AMI they need. To make sure that the AMI is from a trusted source in the AWS marketplace, the search needs to include the 'owners' attribute, otherwise the risk of a whoAMI name confusion attack increases. The whoAMI attack is possible due to misconfigured AMI selection in AWS environments: These conditions allow the attackers to insert malicious AMIs in the selection process by naming the resource similarly to a trusted one. Without specifying an an owner, AWS returns all matching AMIs, including the attacker's. If the parameter "most_rece...

Read full article

Affected Software

3 affected components
Amazon AWS
Amazon Web Services
Amazon Machine Image
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a security vulnerability known as 'whoAMI' that affects Amazon EC2 instances through name confusion attacks.

2

What security implications are discussed?

The security implications include unauthorized access to AWS accounts allowing attackers to execute code on EC2 instances.

3

What products or software are affected?

The affected products include Amazon Web Services, specifically Amazon EC2 and Amazon Machine Images.

4

How does the whoAMI attack work?

The whoAMI attack exploits a naming conflict by allowing attackers to publish an AMI with a specific name to gain access to an AWS account.

5

Who discovered the whoAMI vulnerability?

The whoAMI vulnerability was discovered by security researchers from a security firm.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203