Microsoft Patches Azurescape Bug From Azure Platform

Share post:

Microsoft has fixed a vulnerability in Azure Container Instances, a cloud-based service that allows companies to install packaged applications called containers in the cloud, called Azurescape.

The vulnerability allowed malicious containers to take over containers from other customers on their platforms.

Microsoft has since informed customers who may be affected by the vulnerability to switch their privileged credentials for containers provided on the platform before August 31.

According to Palo Alto Networks researchers who reported Azurescape to Microsoft, the vulnerability “allowed malicious users to compromise the multitenant Kubernetes clusters hosting ACI.”

The researchers also pointed out that the problem started with code used by ACI that was published nearly five years ago and was vulnerable to escaping bugs in the container, so it was sufficient to exploit the vulnerability to break out of the container and execute code with elevated privileges on the underlying machine.

For more information, read the original story in Bleeping Computer.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways