Description
This module performs a container escape onto the host as the daemon user. It takes advantage of the SYS_MODULE capability. If that exists and the linux headers are available to compile on the target, then we can escape onto the host.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/local/docker_privileged_container_kernel_escapemsf undefined(docker_privileged_container_kernel_escape) > show actions ...actions...msf undefined(docker_privileged_container_kernel_escape) > set ACTION < action-name >msf undefined(docker_privileged_container_kernel_escape) > show options ...show and set options...msf undefined(docker_privileged_container_kernel_escape) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub