Open Source Software
CVE-2018-15664 — Docker Elevation of Privilege Vulnerability
Executive Summary
Summary CVE-2018-15664 describes a vulnerability in the Docker runtime (and the underlying community project, Moby) wherein a malicious/compromised container can acquire full read/write access to the host operating system where that container is running. The vulnerability depends on the way that the Docker runtime handles symbolic links and is most directly exploitable through the Docker copy API (‘docker cp’ in the Docker CLI). What is the risk for Azure Kubernetes Service (AKS) and Azure IoT Edge customers? The risk for AKS and Azure IoT Edge customers is minimal as the following need to be true:
Overview
Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
EPSS Score
0.03398
probability of exploitation in the next 30 days
0.8759 percentile - updated 2026-07-25
View on FIRST.org
Affected Products
2 affected products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Azure IoT Edge | Release Notes (Security Update) |
Important | Elevation of Privilege | Maybe |
| Microsoft Azure Kubernetes Service | Release Notes (Security Update) |
Important | Elevation of Privilege | Maybe |
Patches
1 patch
| Article | Type | Restart |
|---|---|---|
Release Notes |
Security Update | Maybe |
Known Exploits
No known exploits have been linked for this CVE yet. When available, exploit references will be sourced from public repositories and may be unverified, incomplete, or non-functional. Always review code carefully before use in any environment.
Acknowledgments
None
References
On This Page