Docker Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Summary CVE-2018-15664 describes a vulnerability in the Docker runtime (and the underlying community project, Moby) wherein a malicious/compromised container can acquire full read/write access to the host operating system where that container is running. The vulnerability depends on the way that the Docker runtime handles symbolic links and is most directly exploitable through the Docker copy API (‘docker cp’ in the Docker CLI). What is the risk for Azure Kubernetes Service (AKS) and Azure IoT Edge customers? The risk for AKS and Azure IoT Edge customers is minimal as the following need to be true: A container on the host must be compromised. The attacker must have access to the host machine, as the docker API is not exposed by default from outside of the host.
🎯 Affected products2
- Azure IoT Edge
- Microsoft Azure Kubernetes Service
✅ Remediation
KBRelease Notes (Security Update)