Published Tue, May 6th, 2025
Platforms
A critical vulnerability in AZNFS-mount utility, preinstalled on Azure HPC/AI images, allowed unprivileged users to escalate privileges to root on Linux machines. The flaw existed in versions up to 2.0.10 and involved a SUID binary. Azure classified it as low severity but fixed it in version 2.0.11.
Azure Blob Storage, Azure HPC, Azure AI
Enable the AZNFS-mount utility's auto-update feature or manually update to version 2.0.11 or later.
No tracked CVEs
Contributed by https://github.com/korniko98
Entry Status
Stub (AI-Generated)
Disclosure Date
-
Exploitability Period
Until 2.0.11
Known ITW Exploitation
-
Detection Methods
Check for the presence of AZNFS-mount utility versions prior to 2.0.11 on Azure HPC/AI workloads or systems using Azure Blob Storage with NFS.
Piercing Index Rating
-
Discovered by
Tal Peleg, Varonis Threat Labs