CVE-2024-29990
published 2024-04-09CVE-2024-29990: Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
PriorityP264critical9CVSS 3.1
AVNACHPRNUINSCCHIHAH
EPSS
18.01%
96.8th percentile
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_kubernetes_service | >= 1.0.0 < 0.3.4 | 0.3.4 |
| microsoft | azure_kubernetes_service_confidential_containers | < 0.3.4 | 0.3.4 |
| msrc | azure_kubernetes_service_confidential_containers | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →An unauthenticated attacker can move the same workload onto a machine they control where the attacker is root, targeting the untrusted AKS Kubernetes node and AKS Confidential Container to take over confidential guests and containers beyond the network stack it might be bound to. ↗
- →Monitor for az confcom extension versions prior to 0.3.3 in use within AKS Confidential Container environments, as these are vulnerable to privilege escalation. ↗
- →Alert on credential theft activity originating from AKS Confidential Container workloads, as successful exploitation allows an attacker to steal credentials and affect resources beyond the AKSCC security scope. ↗
- ·Attack complexity is high (AC:H) because the attacker must prepare the target environment to improve exploit reliability before exploitation can succeed. ↗
- ·No authentication is required; an unauthenticated attacker can move the workload to a machine they control where they are root, bypassing typical authentication controls. ↗
- ·The vulnerability has a scope change impact (S:C), meaning exploitation can affect resources outside the immediate AKS Confidential Container security boundary. ↗
- ·Customers must ensure they are running the latest version of both az confcom and Kata Image to be protected; the vulnerable component version threshold is az confcom < 0.3.3. ↗
CVSS provenance
nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
vendor_msrc9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6gj3-px4j-83rq: Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
ghsa_unreviewed·2024-04-09
CVE-2024-29990 [CRITICAL] CWE-284 GHSA-6gj3-px4j-83rq: Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
Microsoft
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
vendor_msrc·2024-04-09·CVSS 9.0
CVE-2024-29990 [CRITICAL] CWE-284 Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to prepare the target environment to improve exploit reliability.
FAQ: According to the CVSS metric, privileges required is none (PR:N). Does the attacker need to be authenticated?
No. An unauthenticated attacker can move the same workload onto a machine they control, where the attacker is root.
FAQ: According to the CVSS metric, successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
An attacker who successfully exploited this vulnerability could steal credentials
No detection rules found.
No public exploits indexed.
Checkpoint
15th April – Threat Intelligence Report
blogs_checkpoint·2024-04-15
CVE-2024-29990 15th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 15th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 15th April, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Japanese optics giant Hoya Corporation has been a victim of a ransomware attack that impacted its major IT infrastructure and various business divisions. Hunters International ransomware gang claimed responsibility for the attack and demanded a ransom of $10M for alleged 1.7M stolen files.
Check Point Harmony Endpoint and Th
Trendmicro
The April 2024 Security Updates Review
blogs_trendmicro·2024-04-09
The April 2024 Security Updates Review
# The April 2024 Security Updates Review
Get the April 2024 security update and review.
By: Dustin Childs
2024/04/09
Read time: ( words)
Save to Folio
It’s the second Tuesday of the month, and Adobe and Microsoft have released a fresh crop of security updates. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for April 2024
For April, Adobe released nine patches addressing 24 CVEs in Adobe After Effects, Photoshop, Commerce, InDesign, Experience Manager, Media Encoder, Bridge, Illustrator, and Adobe Animate. The largest of these updates is for Experience Manager, however, all of the bugs being patched are simple Cross
Tenable
Microsoft’s April 2024 Patch Tuesday Addresses 147 CVEs (CVE-2024-29988)
blogs_tenable·2024-04-09·CVSS 8.8
[HIGH] Microsoft’s April 2024 Patch Tuesday Addresses 147 CVEs (CVE-2024-29988)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs
blogs_bleepingcomputer·2024-04-09·CVSS 8.1
[HIGH] Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs
## Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs
## Lawrence Abrams
There were also fixes for twenty-six Secure Boot bypasses released this month, including two from Lenovo.
The number of bugs in each vulnerability category is listed below:
31 Elevation of Privilege Vulnerabilities
29 Security Feature Bypass Vulnerabilities
67 Remote Code Execution Vulnerabilities
13 Information Disclosure Vulnerabilities
7 Denial of Service Vulnerabilities
3 Spoofing Vulnerabilities
The total count of 150 flaws does not include 5 Microsoft Edge flaws fixed on April 4th and 2 Mariner flaws. Mariner is an open-source Linux distribution developed by Microsoft for its Microsoft Azure services.
To learn more about the non-security updates released today, you can review our ded
Trendmicro
The April 2024 Security Updates Review
blogs_trendmicro·2024-04-09
The April 2024 Security Updates Review
## The April 2024 Security Updates Review
Get the April 2024 security update and review.
By: Dustin Childs 2024/04/09 Read time: ( words)
Save to Folio
It’s the second Tuesday of the month, and Adobe and Microsoft have released a fresh crop of security updates. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for April 2024
For April, Adobe released nine patches addressing 24 CVEs in Adobe After Effects, Photoshop, Commerce, InDesign, Experience Manager, Media Encoder, Bridge, Illustrator, and Adobe Animate. The largest of these updates is for Experience Manager , however, all of the bugs being patched are simple Cros
2024-04-09
Published