Vulnerabilities

Microsoft fixes bug that let hackers hijack Azure Linux clusters

0

Microsoft has fixed a container escape vulnerability in the Service Fabric (SF) application hosting platform that would let hackers to escalate privileges to root, gain control of the host node, and compromise the entire SF Linux cluster.

Service Fabric is a platform for business-critical applications that hosts over 1 million apps. It also powers many Microsoft products, which includes Azure SQL Database, Azure Cosmos DB, Microsoft Intune, Azure Event Hubs, Azure IoT Hub, Dynamics 365, Skype for Business, Cortana, Microsoft Power BI, and multiple core Azure services.

The SF security flaw which is tracked as CVE-2022-30137 was dubbed FabricScape by Palo Alto Networks’ Unit 42 researchers. The researchers discovered it and reported it to Microsoft on January 30.

The flaw is due to a race-conditioned arbitrary write in the Data Collection Agent (DCA) Service Fabric component (running as root) that enables attackers to overwrite files in the node file system with malicious content by creating symlinks to gain code execution.

Microsoft recommends that customers continue to review all containerized workloads (both Linux and Windows) which are permitted access to their host clusters.

By default, an SF cluster is a single-tenant environment and thus there is no isolation between applications. Creating isolation is possible and additional guidance on hosting untrusted code can be found on the Azure Service Fabric security best practices page.

Microsoft Azure Service Fabric 9.0 Cumulative Update was released on June 14 according to Unit 42’s report.

Fixes for this flaw have been pushed to automatically updated Linux clusters starting on June 14, after the security advisory detailing the bug was published.

Customers who have enabled automatic updates on their Linux clusters does not have to take any further action. Those running Azure Service Fabric without automatic updates are advised to upgrade their Linux clusters to the most recent Service Fabric release at the earliest.

Palo Alto Networks urge organizations to take immediate action to identify whether their environments are vulnerable and quickly implement patches if they are.

The customers that haven’t enabled automatic updates have been notified about this issue by Microsoft via portal notifications sent through Azure Service Health.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

ZuoRAT malware targets SOHO routers to spy on victims

Previous article

Russian hacktivists take down Norway govt sites in DDoS attacks

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *