Home/News/Kimi K3 Agents Discovered Redis Zero-Days, Created RCE Exploit
The Hacker News1 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Kimi K3 Agents Discovered Redis Zero-Days, Created RCE Exploit

Kimi K3 Agents Discovered Redis Zero-Days, Created RCE Exploit

Kimi K3 AI agents discovered multiple zero-day vulnerabilities within Redis, subsequently developing proof-of-concept (PoC) exploits that demonstrate remote code execution (RCE) capabilities. These findings were disclosed, prompting Redis to release seven security updates on July 23.

The identified vulnerabilities affect specific versions of Redis, including stock versions 6.2.22, 7.4.9, 8.6.4, and 8.8.0. The researchers' PoCs indicate that all four exploit chains necessitate the use of the RESTORE command. Furthermore, for the Streams chains, the exploits also require the EVAL command and XGROUP functionality. The exploit targeting version 8.8.0 specifically needs EVAL and the bundled RedisBloom module.

According to Redis's advisory, the underlying memory flaws present in these versions are the root cause of the potential for remote code execution. The security releases provided by Redis address these issues. The updated versions include Redis 6.2.23, 7.2.15, and 7.4.10, among others, which are intended to mitigate the risks associated with these newly discovered vulnerabilities.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next