| CVE ID | |
| CVSS SCORE | 9.9, AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| AFFECTED VENDORS |
Microsoft |
| AFFECTED PRODUCTS |
GitHub |
| VULNERABILITY DETAILS |
This vulnerability allows remote attackers to escalate privileges on Microsoft GitHub. Authentication is required to exploit this vulnerability. The specific flaw exists within the configuration of Dev-Containers. The application does not enforce the privileged flag within a devcontainer configuration. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the host. |
| ADDITIONAL DETAILS |
11/03/23 – ZDI reported the vulnerability to the vendor. -- Mitigation: Given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the application |
| DISCLOSURE TIMELINE |
|
| CREDIT | Nitesh Surana (@_niteshsurana) of Trend Micro Research |