Confidential Container Elevation of Privilege Vulnerability
CVE-2024-21403

9CRITICAL

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
13 February 2024

Summary

The vulnerability identified in Microsoft Azure Kubernetes Service allows for the elevation of privilege within confidential containers. This vulnerability can be potentially exploited by attackers to gain unauthorized access to sensitive information or perform actions beyond their intended permissions. This underscores the importance of implementing effective security measures within cloud environments to safeguard against potential breaches and maintain the integrity of containerized applications.

Affected Version(s)

Azure Kubernetes Service Unknown 1.0.0 < 0.3.3

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.