services / Azure / Fleet hub Kubernetes initializer configurations
Initializer configurations are cluster-scoped Kubernetes admission-control objects on the Fleet Manager hub cluster that register interceptors which can gate or mutate objects during admission to the API server.
Admission-control configuration is a cluster-admin-tier security primitive; controlling it can influence every object created cluster-wide.
Microsoft.ContainerService/fleets/admissionregistration.k8s.io/initializerconfigurations/write
Writing an initializer configuration registers an admission interceptor that can mutate objects admitted cluster-wide (inject privileged/mutated resources), enabling privilege escalation, tampering with admitted workloads, and bypass of other admission-based defenses.
Risks
Scope: CRITICAL
This privilege may grant access to sensitive data from a significant fraction of organizational functions, allow interruption of critical organizational services, or its exploit could lead to significant privilege escalation.
Links
Contributed by P0 Security