Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2024-29990

Опубликовано: 09 апр. 2024
Источник: msrc
CVSS3: 9
EPSS Низкий

Описание

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

FAQ

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?

Successful exploitation of this vulnerability requires an attacker to prepare the target environment to improve exploit reliability.

According to the CVSS metric, privileges required is none (PR:N). Does the attacker need to be authenticated?

No. An unauthenticated attacker can move the same workload onto a machine they control, where the attacker is root.

According to the CVSS metric, successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?

An attacker who successfully exploited this vulnerability could steal credentials and affect resources beyond the security scope managed by Azure Kubernetes Service Confidential Containers (AKSCC).

How could an attacker exploit this vulnerability?

An attacker can access the untrusted AKS Kubernetes node and AKS Confidential Container to take over confidential guests and containers beyond the network stack it might be bound to.

Is there any action I need to take to be protected from this vulnerability?

Customer must ensure they are running the latest version of az confcom and Kata Image.

Customers who do not have az confcom installed can install the latest version by executing az extension add -n confcom. Customers who are running versions prior to 0.3.3 need to update by executing az extension update -n confcom. For more information, reference:

Обновления

ПродуктСтатьяОбновление
Azure Kubernetes Service Confidential Containers

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 92%
0.08805
Низкий

9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9
nvd
почти 2 года назад

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

CVSS3: 9
github
почти 2 года назад

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

CVSS3: 9
fstec
почти 2 года назад

Уязвимость программного обеспечения развертывания и управления конфиденциальными контейнерами Azure Kubernetes Service Confidential Containers, связанная с недостатками контроля доступа, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 92%
0.08805
Низкий

9 Critical

CVSS3