CVE ID | |
CVSS SCORE | 9.9, AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
AFFECTED VENDORS |
Microsoft |
AFFECTED PRODUCTS |
GitHub |
VULNERABILITY DETAILS |
This vulnerability allows remote attackers to escalate privileges on Microsoft GitHub. Authentication is required to exploit this vulnerability. The specific flaw exists within the configuration of Dev-Containers. The application does not enforce the privileged flag within a devcontainer configuration. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the host. |
ADDITIONAL DETAILS |
11/03/23 – ZDI reported the vulnerability to the vendor. -- Mitigation: Given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the application |
DISCLOSURE TIMELINE |
|
CREDIT | Nitesh Surana (@_niteshsurana) of Trend Micro Research |