CVE-2020-15257 is a privilege-escalation/container-escape vulnerability in containerd affecting versions before 1.3.9 and 1.4.3. The issue arises because containerd-shim exposed its ttrpc API over abstract Unix domain sockets that were reachable from containers sharing the shim's network namespace. Access control on the shim socket relied on UnixSocketRequireSameUser-style checks that verified the connecting process had the same effective UID/GID as the shim, but did not otherwise restrict access to the abstract socket. In typical deployments, containerd-shim runs as root, so a process running as effective UID 0 inside a host-network container could satisfy the check even with otherwise reduced privileges. An attacker able to connect to the shim API could invoke operations such as Create and Start to cause new processes to be launched with elevated privileges, leading to host compromise. The vulnerability was fixed by containerd in 1.3.9 and 1.4.3; content also notes backports for some 1.2.x distributions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Go-based proof-of-concept exploit for CVE-2020-15257, targeting containerd (versions 1.2.x, 1.3.x, and pre-patch 1.4.x) on Linux. The exploit demonstrates how a container with host networking can escalate privileges to root on the host by abusing containerd's shim and bundle mechanisms. The main exploit logic is in 'main.go', which orchestrates several stages: connecting to containerd's abstract Unix sockets, creating new tasks with manipulated bundles, and reading/writing files on the host filesystem (e.g., /tmp/shimmer.out, /etc/crontab, /proc/1/root/tmp/shimmer.out). The exploit can extract sensitive information and execute commands as root on the host. The repository includes a Dockerfile for building and running the exploit in a containerized environment. The README provides detailed usage instructions and notes about the side effects on Docker/containerd state after exploitation. This is a functional proof-of-concept exploit, not a detection script, and demonstrates a real privilege escalation path on vulnerable systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in containerd allowing full root container escape in certain configurations.
A container escape / host-compromise vulnerability in containerd where host-networked containers running as real root can connect to exposed abstract Unix domain sockets used by containerd-shim and abuse its API to achieve arbitrary code execution on the host.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.