PT-2024-3523 · Microsoft · Azure Kubernetes Service

Yuval Avrahami

·

Published

2024-04-09

·

Updated

2025-09-16

·

CVE-2024-29990

CVSS v2.0

9.3

Critical

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Azure Kubernetes Service Confidential Container (affected versions not specified)
Description The issue is related to a lack of access control in the deployment and management of confidential containers in Azure Kubernetes Service, which can be exploited by a remote attacker to elevate their privileges. This could potentially allow unauthenticated attackers to gain full control of Azure Kubernetes clusters, including stealing credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-03825
CVE-2024-29990

Affected Products

Azure Kubernetes Service