CVE-2022-30137
MEDIUMService Fabric - Elevation of Privilege via Docker Container
Title source: llmDescription
Executive Summary An Elevation of Privilege (EOP) vulnerability has been identified within Service Fabric clusters that run Docker containers. Exploitation of this EOP vulnerability requires an attacker to gain remote code execution within a container. All Service Fabric and Docker versions are impacted.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30137
Patch, Vendor Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-30137
Scores
CVSS v3
6.7
EPSS
0.0116
EPSS Percentile
64.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (1)
microsoft/service_fabric
Published
Jun 15, 2022
Tracked Since
Feb 18, 2026