GPU VulnDB

Database/Container, Kubernetes & orchestration

AKS Confidential Containers: elevation of privilege across the confidential container boundary

CVSS 9.0CVE-2024-21400Container, Kubernetes & orchestrationcurated

Impact

Microsoft describes this only as an elevation of privilege in Azure Kubernetes Service Confidential Containers, scored 9.0 with a changed scope, meaning the flaw lets an attacker gain privileges beyond the component that is broken. The affected product list covers AKS and the confcom tooling used to generate confidential container security policies. For an operator running confidential workloads on AKS - the pattern used when tenant data must stay opaque to the platform - the guarantee being weakened is the one the deployment exists for. The NVD record carries no technical detail beyond the MSRC title, so the exact path is not established here; read the MSRC entry before drawing conclusions about your configuration.

Who can reach it

Network-reachable with no privileges and no user interaction per the CVSS vector, at high attack complexity. The record does not describe what the attacker must reach, so treat the attack path as unestablished.

What to do

Microsoft fixed this service-side and in the tooling; follow the MSRC guidance for CVE-2024-21400, which includes updating the az confcom extension and rotating affected confidential container security policies. Because AKS is a managed control plane, most of the fix is not yours to schedule - the operator action is updating tooling and regenerating policies, not draining nodes.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.