
Proof of concept code for breaking out of docker via runC
A proof of concept code for CVE-2019-5736
This POC is heavily based on YuvalAvra's POC. I do not claim any credit for the code utilised in this POC.
More information about this vulnerability and a demonstration of how it can be exploited can be found in the worksheet. Information in the worksheet is based a blog post by Twistlock Labs.
This POC has the ability to modify binaries on the host system, therefore, is recommended to be conducted in a virtual machine.
The POC overwrites runC on the host machine with code to setup a persistent remote desktop using VNC
Clone the repository:
$ git clone https://github.com/RyanNgWH/CVE-2019-5736-POC
Build and run the Docker image:
$ docker build -t image_name:latest /path/to/malicious_image_POC
$ docker run --rm image_name:latest