Exploitation of Deep Learning Framework Vulnerabilities
深度學習框架漏洞遭利用
Design & Development
Risk Description
When an organization's inference service runs a framework version with known vulnerabilities; due to unmitigated control gaps, an attacker exploits one to gain execution privileges and move laterally into the internal network, triggering external stakeholder impacts and causing the organization's patching process does not cover AI-related components, leaving the vulnerability unaddressed for an extended period.
Framework Mappings
OWASP Top 10 for LLMLLM03
MITRE ATLASAML.T0010
NIST CSF 2.0PR.PS、DE.CM
ISO/IEC 42001Annex A.10.3
ISO/IEC 5338設計與開發
Risk Treatment & Implementation Guidance
Include AI frameworks and inference components in vulnerability scanning and patch management; Segment inference services on the network to limit lateral movement after compromise; Automate scanning with patching deadlines for known vulnerabilities