UNKNOWN Microsoft PoC
CVE-2024-21626
GitHub: CVE-2024-21626 Container breakout through process.cwd trickery and leaked fds
Microsoft Security Update 2024-Feb: GitHub: CVE-2024-21626 Container breakout through process.cwd trickery and leaked fds
Affected Products
- Azure Kubernetes Service
- CBL Mariner 2.0 ARM
- CBL Mariner 2.0 x64
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21626
- https://nvd.nist.gov/vuln/detail/CVE-2024-21626
This unknown severity vulnerability was published on 2024-02-13 via Microsoft. 🚨 A public proof-of-concept exploit is available on GitHub. EPSS score: 18.1% (top 3% of all CVEs by exploitation probability). Affected: Azure Kubernetes Service, CBL Mariner 2.0 ARM, CBL Mariner 2.0 x64.
vulnfeed aggregates 7759 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.