Azure AKS Backup Privilege Flaw: Silent Patch Suspected, No CVE Issued

1 min read
Source: BleepingComputer
Azure AKS Backup Privilege Flaw: Silent Patch Suspected, No CVE Issued
Photo: BleepingComputer
TL;DR

Security researcher Justin O'Leary alleges a critical privilege-escalation flaw in Azure Backup for AKS could let a low-privileged user become cluster-admin via Trusted Access; Microsoft rejected the report as expected behavior with no product changes and blocked CVE issuance, while CERT/CC independently validated the bug and assigned VU#284781. After disclosure, Microsoft reportedly changed behavior and added permission checks, suggesting a silent patch; no public advisory or CVE was issued, leaving defenders with limited visibility into exposure and remediation timelines.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer