We are currently reviewing security vulnerabilities identified by our container security scanning solution in Microsoft-provided container images running within our Azure Kubernetes Service (AKS) environments.
The findings relate primarily to images hosted under mcr.microsoft.com that appear to be associated with AKS system components, Kubernetes CSI drivers, Azure networking components, Azure Monitor / Container Insights, Microsoft Defender for Containers, CoreDNS, Metrics Server, and other Microsoft-managed or Microsoft-supported AKS components.
Our production AKS environment is currently running Kubernetes version 1.34.4 and is healthy and operational. However, the vulnerability scanner continues to report multiple Critical and High severity vulnerabilities in Microsoft-provided system images.
Similar findings are also present across our other AKS environments.
Vulnerability Findings
Examples identified in the latest security scan include:
Azure Monitor / Container Insights
mcr.microsoft.com/azuremonitor/containerinsights/ciprod:3.4.0
mcr.microsoft.com/azuremonitor/containerinsights/ciprod/prometheus-collector/images:7.2.0-main-07-27-2026-2169504d
mcr.microsoft.com/azuremonitor/containerinsights/ciprod/prometheus-collector/images:7.2.0-main-07-27-2026-2169504d-targetallocator
Azure File / Disk CSI Components
mcr.microsoft.com/oss/v2/kubernetes-csi/azurefile-csi:v1.34.6
mcr.microsoft.com/oss/v2/kubernetes-csi/azuredisk-csi:v1.33.10
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.16.0-3
mcr.microsoft.com/oss/v2/kubernetes-csi/csi-node-driver-registrar:v2.15.0-7
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.18.0-3
Secrets Store CSI Components
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.6-2
mcr.microsoft.com/oss/v2/azure/secrets-store/provider-azure:v1.7.2-7
AKS / Kubernetes System Components
mcr.microsoft.com/oss/v2/kubernetes/kube-proxy:v1.34.4-8
mcr.microsoft.com/oss/v2/kubernetes/coredns:v1.13.1-13
mcr.microsoft.com/oss/v2/kubernetes/metrics-server:v0.8.0-14
mcr.microsoft.com/oss/v2/kubernetes/azure-cloud-node-manager:v1.34.11-1
mcr.microsoft.com/oss/v2/kubernetes/apiserver-network-proxy/agent:v0.32.1-7
AKS Networking Components
mcr.microsoft.com/containernetworking/retina-agent:v1.2.3
mcr.microsoft.com/containernetworking/retina-init:v1.2.3
mcr.microsoft.com/containernetworking/azure-cni:v1.7.16-0
mcr.microsoft.com/oss/v2/azure/ip-masq-agent-v2:v0.1.16-6
Microsoft Defender for Containers Components
mcr.microsoft.com/azuredefender/stable/low-level-collector:2.0.244
mcr.microsoft.com/azuredefender/stable/old-file-cleaner:1.1.59
mcr.microsoft.com/azuredefender/stable/security-publisher:1.1.64
mcr.microsoft.com/azuredefender/stable/pod-collector:1.0.249
AKS Environment
Our production AKS cluster is currently running:
- Kubernetes / AKS version: 1.34.4
- Cluster status: Healthy / Running
The vulnerability findings are also observed in other AKS environments. We can provide the exact AKS versions and configuration details for those environments privately to the assigned Microsoft support engineer.
For security and privacy reasons, we are intentionally not including subscription IDs, tenant IDs, resource group names, AKS cluster names, node details, internal infrastructure information, or the complete vulnerability/CVE export in this public post.
We can provide all relevant environment-specific information through a private Microsoft support channel.
Guidance Requested from Microsoft
We would appreciate clarification from the Microsoft AKS technical team on the following:
- Microsoft ownership Can Microsoft confirm which of the above images are Microsoft-managed AKS/system components or Microsoft-managed AKS add-ons?
- Supported remediation For Critical and High vulnerabilities in these Microsoft-managed images, what is the supported remediation procedure?
- Upgrade mechanism Should these vulnerabilities be remediated through:
- AKS Kubernetes version upgrade
- AKS patch version upgrade
- AKS node image upgrade
- Managed AKS add-on update
- CSI driver update
- Azure CNI/networking component update
- Azure Monitor / Container Insights update
- Microsoft Defender for Containers update
- or another Microsoft-managed update mechanism?
- Manual image replacement Are customers expected to manually replace or override any of these container images? Our understanding is that manually changing Microsoft-managed AKS system images may not be supported, so we would like Microsoft to confirm the correct remediation approach.
- Vulnerability applicability For the reported Critical and High vulnerabilities, could Microsoft confirm whether they are:
- applicable and exploitable in AKS,
- non-exploitable in the current AKS configuration,
- known false-positive scanner findings,
- already mitigated by the AKS platform,
- or currently awaiting an updated Microsoft image?
- Patched versions Where remediation is available, could Microsoft identify the relevant:
- AKS version,
- component/add-on version,
- node image version,
- or container image version
that contains the security fix?
- Outstanding vulnerabilities Where no fixed image is currently available, could Microsoft provide:
- recommended mitigation,
- security advisory or documentation,
- current remediation status,
- and expected updated component/image version where available?
ISO 27001 Requirement
Our organization is currently preparing for ISO 27001 certification.
As part of our vulnerability management process, we need to appropriately remediate or document Critical and High severity vulnerabilities, including findings associated with Microsoft-managed infrastructure components.
For vulnerabilities that cannot be remediated directly by us, we need appropriate evidence showing the Microsoft ownership/status of the affected component, supported remediation guidance, mitigation, or confirmation of vulnerability applicability.
Request for Technical Support
Due to the sensitive nature of our production and other AKS environments, we do not want to provide detailed infrastructure information or the complete CVE report in this public forum.
Could this issue please be reviewed or escalated to a Microsoft Azure/AKS technical support engineer?
Once connected privately with the appropriate technical engineer, we can provide:
- Complete CVE/vulnerability export
- Affected AKS cluster versions
- Subscription and resource details
- Node pool and node image information
- AKS add-on configuration
- Defender for Containers configuration
- Azure Monitor configuration
- Individual CVE details
- Screenshots and scanner evidence
- Any additional diagnostic information required
Our primary objective is to understand the Microsoft-supported remediation path for these Critical and High vulnerabilities in Microsoft-managed AKS container images and obtain appropriate guidance for our ISO 27001 vulnerability management process.