3 ms·
How does allowPrivilegeEscalation=False help?
by cpach 5mo ago
How does allowPrivilegeEscalation=False help?
- atmosx 5mo agoHave you tested running the PoC in a pod with and without proviEsc set?
- cpach 5mo agoNo, I haven’t. My concern is to try to understand the mechanisms of the exploit. Copy Fail is not simply ”hey, kernel, give me root”. I would say it’s more general than that. It’s rather: ”Hey, kernel, when you present file /foo to a process, make the contents of that file appear according to my wishes”. Which can be used (in various ways) to advance the attacker’s position. That’s why I think it’s interesting to ponder if that power allows the attacker to simply sneak past security policies such as allowPrivilegeEscalation=false.