CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-21376

CVSS 9.0v3.1pub. 2024-02-13upd. 2026-08-10

Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability

🤖 AI Analysis
How it works

The vulnerability affects the Confidential Containers component in Azure Kubernetes Service and allows an unauthenticated attacker to execute code remotely over the network (AV:N). The attack requires high complexity (AC:H), but does not require any privileges or user interaction. A successful exploit leads to a security breach beyond container boundaries (scope changed — S:C), indicating the possibility of escape from the isolated container environment.

Impact

An attacker can remotely execute arbitrary code in the context of Confidential Containers, potentially taking control of the isolated environment and gaining access to sensitive data, as well as affecting system integrity and availability.

Mitigation & patch

Patches available from the vendor must be applied in accordance with references — the update described in the Microsoft Security Response Center at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21376. It is recommended to monitor AKS environments with the Confidential Containers feature enabled and to limit network exposure of clusters.

Who is affected

Microsoft Azure Kubernetes Service — Confidential Containers component; specific versions indicated in vendor references (MSRC).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Microsoft Azure Kubernetes Service

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEContainer
CWE
References

Related vulnerabilities

CVE-2026-50516CRITICAL9.4same product

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized atta...

CVE-2026-56163CRITICAL10.0PL ✓same product

Brak uwierzytelnienia w Microsoft Azure Kubernetes Service — privilege escalation

CVE-2026-33105CRITICAL10.0PL ✓same product

Nieprawidłowa autoryzacja w Microsoft Azure Kubernetes Service — eskalacja uprawnień

CVE-2024-21403CRITICAL9.0PL ✓same product

Privilege escalation w Azure Kubernetes Service Confidential Containers

CVE-2023-29332HIGH7.5same product

Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability