Service Fabric Privilege Escalation from Containerized Workloads on Linux

  • Thread starter Thread starter MSRC
  • Start date Start date
M

MSRC

Under Coordinated Vulnerability Disclosure (CVD), cloud-security vendor Palo Alto Networks informed Microsoft of an issue affecting Service Fabric (SF) Linux clusters (CVE-2022-30137). The vulnerability enables a bad actor, with access to a compromised container, to escalate privileges and gain control of the resource’s host SF node and the entire cluster.

Continue reading...
 
Back
Top