OVERVIEW CVE-2025-57851 is a container privilege escalation vulnerability affecting Multicluster Engine for Kubernetes images. The flaw stems from the /etc/passwd file being created with group-writable permissions during the container build process, allowing an attacker with container command execution privileges to modify the file and escalate to root access. SEVERITY The vulnerability carries a CVSS 3.1 score of 6.4 (Medium) with a local attack vector requiring high privileges but no user interaction. While the attack complexity is high, successful exploitation grants complete compromise of container confidentiality, integrity, and availability through arbitrary UID assignment, including root-level access (UID 0). An attacker would need existing container execution capabilities, typically gained through compromised applications or legitimate container access. EXPLOITATION STATUS This vulnerability shows minimal exploitation activity and community attention. It is not listed on the CISA KEV (Known Exploited Vulnerabilities) catalog, indicating no confirmed active exploitation in the wild. The EPSS score of 0.00007 places it well below the average CVE, suggesting low real-world exploitation likelihood. No public exploit code appears widely available at this time. The inactive status on exploit tracking lists indicates this remains primarily a theoretical risk requiring specific preconditions for successful exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:advanced_cluster_management_for_kubernetes:-:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE match | cpe:2.3:a:redhat:multicluster_engine_for_kubernetes:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.