Confidential Container Elevation of Privilege Vulnerability
CVE-2024-21403
9CRITICAL
Summary
The vulnerability identified in Microsoft Azure Kubernetes Service allows for the elevation of privilege within confidential containers. This vulnerability can be potentially exploited by attackers to gain unauthorized access to sensitive information or perform actions beyond their intended permissions. This underscores the importance of implementing effective security measures within cloud environments to safeguard against potential breaches and maintain the integrity of containerized applications.
Affected Version(s)
Azure Kubernetes Service Unknown 1.0.0 < 0.3.3
References
CVSS V3.1
Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre DatabaseMicrosoft Feed