Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
The vulnerability affects the Confidential Containers component in Azure Kubernetes Service and allows an unauthenticated attacker to execute code remotely over the network (AV:N). The attack requires high complexity (AC:H), but does not require any privileges or user interaction. A successful exploit leads to a security breach beyond container boundaries (scope changed — S:C), indicating the possibility of escape from the isolated container environment.
An attacker can remotely execute arbitrary code in the context of Confidential Containers, potentially taking control of the isolated environment and gaining access to sensitive data, as well as affecting system integrity and availability.
Patches available from the vendor must be applied in accordance with references — the update described in the Microsoft Security Response Center at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21376. It is recommended to monitor AKS environments with the Confidential Containers feature enabled and to limit network exposure of clusters.
Microsoft Azure Kubernetes Service — Confidential Containers component; specific versions indicated in vendor references (MSRC).
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HMicrosoft Azure Kubernetes Service
APPMicrosoftall versions
Related vulnerabilities
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized atta...
Brak uwierzytelnienia w Microsoft Azure Kubernetes Service — privilege escalation
Nieprawidłowa autoryzacja w Microsoft Azure Kubernetes Service — eskalacja uprawnień
Privilege escalation w Azure Kubernetes Service Confidential Containers
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability