Nullcon Goa 2025: Breaking Boundaries & Demystifying Kernel SU 4 Root Access In Azure Cloud Shell
About this talk
This talk explores the Use-After-Free vulnerability and advanced RCU techniques in the Netfilter module of kernel versions 5.10.102.2-microsoft-standard and prior 6.9, which are integral to the Azure Cloud Shell environment. The speakers detail how successful exploitation of these kernel vulnerabilities can lead to elevated privileges within a user's Cloud Shell, potentially resulting in container escape and elevated access to cloud resources. They also explain the security measures in place, emphasizing the non-shared kernel and isolated hypervisor VM architecture of Azure Cloud Shell, which helps maintain security across user sessions despite the risks posed by such vulnerabilities.
More from this event
See all 30 talks →
Nullcon Goa 2025: Securing the chains: Building defensive layers for software supply chains
38:14
Nullcon Goa 2025 | Large-Scale Exposure Of Orphaned Commits On Major Git Platforms by Kumar Ashwin
26:30
Nullcon Goa 2025 | Panel: Modernizing Security Architecture: Platforms or Best-of-Breed, What Works?
44:47
Nullcon Goa 2025: Panel | Cyber Fusion Center: The Command Center For Integrated Cyber Defense
42:01