CVE-2024-29990: Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
Published Apr 9, 2024
·Updated
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
Affected Software
2 affected componentsFixes available
Microsoft Azure Kubernetes Service Confidential Containers
Microsoft Azure Kubernetes Service Confidential Containers<0.3.4
Event History
Apr 9, 2024
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverity
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-29990?
CVE-2024-29990 has been rated as having a high severity due to its potential for elevation of privilege.
2
How do I fix CVE-2024-29990?
To address CVE-2024-29990, apply the recommended patches and update the Azure Kubernetes Service Confidential Containers to the latest version.
3
What products are affected by CVE-2024-29990?
CVE-2024-29990 affects the Microsoft Azure Kubernetes Service Confidential Containers up to version 0.3.4.
4
What type of vulnerability is CVE-2024-29990?
CVE-2024-29990 is categorized as an elevation of privilege vulnerability.
5
Can CVE-2024-29990 lead to unauthorized access?
Yes, CVE-2024-29990 can allow local users to gain higher privileges, leading to unauthorized access to sensitive container resources.