Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2024-21376

Опубликовано: 13 фев. 2024
Источник: msrc
CVSS3: 9
EPSS Низкий

Описание

Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability

FAQ

Is there any action I need to take to be protected from this vulnerability?

Customer must ensure they are running the latest version of az confcom and Kata Image.

Customers who do not have az confcom installed can install the latest version by executing az extension add -n confcom. Customers who are running versions prior to 0.3.3 need to update by executing az extension update -n confcom. For more information, reference:

According to the CVSS metric, successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?

An attacker who successfully exploited this vulnerability could steal credentials and affect resources beyond the security scope managed by Azure Kubernetes Service Confidential Containers (AKSCC).

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?

Successful exploitation of this vulnerability requires an attacker to prepare the target environment to improve exploit reliability.

How could an attacker exploit this vulnerability?

An attacker can access the untrusted AKS Kubernetes node and AKS Confidential Container to take over confidential guests and containers beyond the network stack it might be bound to.

According to the CVSS metric, privileges required is none (PR:N). Does the attacker need to be authenticated?

No. An unauthenticated attacker can move the same workload onto a machine they control, where the attacker is root.

Обновления

ПродуктСтатьяОбновление
Azure Kubernetes Service Confidential Containers

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 51%
0.00275
Низкий

9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9
nvd
почти 2 года назад

Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability

CVSS3: 9
github
почти 2 года назад

Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability

CVSS3: 9
fstec
почти 2 года назад

Уязвимость программного обеспечения развертывания и управления конфиденциальными контейнерами Azure Kubernetes Service Confidential Containers, связанная с недостаточной проверкой входных данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 51%
0.00275
Низкий

9 Critical

CVSS3