Azure AKS Backup Privilege Flaw: Silent Patch Suspected, No CVE Issued

1 min read
Source: BleepingComputer
Azure AKS Backup Privilege Flaw: Silent Patch Suspected, No CVE Issued
Photo: BleepingComputer
TL;DR Summary

Security researcher Justin O'Leary alleges a critical privilege-escalation flaw in Azure Backup for AKS could let a low-privileged user become cluster-admin via Trusted Access; Microsoft rejected the report as expected behavior with no product changes and blocked CVE issuance, while CERT/CC independently validated the bug and assigned VU#284781. After disclosure, Microsoft reportedly changed behavior and added permission checks, suggesting a silent patch; no public advisory or CVE was issued, leaving defenders with limited visibility into exposure and remediation timelines.

Share this article

Reading Insights

Total Reads

0

Unique Readers

16

Time Saved

5 min

vs 6 min read

Condensed

93%

1,08079 words

Want the full story? Read the original article

Read on BleepingComputer