News: 1656510010

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

FabricScape: Microsoft warns of vuln in containerized Linux workloads

(2022/06/29)


Microsoft is flagging up a Service Fabric privilege escalation from containerized workloads on Linux and urging customers to upgrade their clusters to the most recent release.

The issue stems from [1]CVE-2022-30137 , an elevation-of-privilege vulnerability. An attacker would need read/write access to the cluster as well as the ability to execute code within a container granted access to the Service Fabric runtime in order to wreak havoc.

Through a compromised container, a miscreant could gain control of the resource's host Service Fabric node and potentially the entire cluster.

[2]

"Though the bug exists on both Operating System (OS) platforms," [3]said Microsoft , "it is only exploitable on Linux; Windows has been thoroughly vetted and found not to be vulnerable to this attack."

[4]

[5]

It's unusual to see the words "Windows" and "thoroughly vetted" in the context of security. This time, however, the problem is to do with Linux containers.

The findings [6]were reported responsibly by Palo Alto networks , and the issue has been patched (customers using auto-update should have already received the fix). Microsoft has also rolled out the mitigation to products powered by the tech.

[7]OpenSSL 3.0.5 awaits release to fix potential worse-than-Heartbleed flaw

[8]Cisco warns of security holes in its security appliances

[9]Microsoft fixes under-attack Windows zero-day Follina

[10]Atlassian: Unpatched years-old flaw under attack right now to hijack Confluence

The vulnerability has been dubbed "FabricScape" by researchers. Microsoft's Service Fabric is commonly used with Azure and hosts more than one million applications. It lurks beneath the likes of Azure SQL Database and CosmosDB as well as Redmond buzzphrase of the day, Power BI. As such, discovering a hole can be poked in it is somewhat discomfiting.

As with so many vulnerabilities, the issue is magnified by defaults. Runtime access for the container is required by the exploit which, alas, is granted by default. Microsoft helpfully documented the steps required for a successful attack: first compromise a containerized workload deployed by the owner of a Linux Service Fabric cluster. Then substitute an index file read by the Service Fabric Diagnostics Collection Agent (DCA) with a symlink. Use an additional timing attack and control of the machine hosting the Service Fabric node is all yours.

[11]

"By design," said Microsoft, "root access on the machine hosting the SF note is not considered a security boundary in an SF cluster; the highest privileged role on a node is equally privileged anywhere in the same cluster."

The patch, according to Microsoft, is "to further strengthen the security in the Linux cluster by adapting the principle of path to least privilege." ®

Get our [12]Tech Resources



[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30137

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yrx3InVCDMHs-013RuU1jQAAAMw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://msrc-blog.microsoft.com/2022/06/28/azure-service-fabric-privilege-escalation-from-containerized-workloads-on-linux/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yrx3InVCDMHs-013RuU1jQAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yrx3InVCDMHs-013RuU1jQAAAMw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://unit42.paloaltonetworks.com/fabricscape-cve-2022-30137/

[7] https://www.theregister.com/2022/06/27/openssl_304_memory_corruption_bug/

[8] https://www.theregister.com/2022/06/22/cisco_bug_bundle/

[9] https://www.theregister.com/2022/06/15/microsoft_patch_tuesday/

[10] https://www.theregister.com/2022/06/03/atlassian_confluence_critical_flaw_attacked/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yrx3InVCDMHs-013RuU1jQAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://whitepapers.theregister.com/



"Windows has been thoroughly vetted"

Pascal Monett

Oh really ?

You don't say. By who ?

Maybe you get some of those guys to thoroughly vet your updates as well ?

Silly me, I need some more frog pills . . .

Re: "Windows has been thoroughly vetted"

ITMA

The Vet - Windows 11 has been well and truly neutered.

This page intentionally left blank.