CVE-2025-64324 is a logic bug in the KubeVirt hostDisk feature, specifically with the DiskOrCreate option, affecting versions prior to 1.6.1 and 1.7.0. This flaw allows an attacker to read and write arbitrary files owned by more privileged users on the host system. With a CVSS score of 7.7 (HIGH), it presents a significant risk due to its low attack complexity and potential for high confidentiality and integrity impact. There is no known active exploitation, publicly available exploit code, or KEV entry. Community discussion and media coverage are minimal, with only one mention and one article identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.1CPE matchmatch criteria | cpe:2.3:a:kubevirt:kubevirt:*:*:*:*:*:kubernetes:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:kubevirt:kubevirt:1.7.0:alpha0:*:*:*:kubernetes:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:kubevirt:kubevirt:1.7.0:beta0:*:*:*:kubernetes:*:* | ||
>= 0, < 1.6.1CPE match | cpe:2.3:a:kubevirt:kubevirt:*:alpha6:*:*:*:kubernetes:*:* | ||
>= 1.7.0-alpha.0, < 1.7.0-rc.0CPE match | cpe:2.3:a:kubevirt:kubevirt:*:alpha6:*:*:*:kubernetes:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
kubevirt.io/kubevirt: KubeVirt: Arbitrary file read/write and privilege escalation via hostDisk feature
Nov 18, 2025KubeVirt Vulnerable to Arbitrary Host File Read and Write
Nov 11, 2025KubeVirt Vulnerable to Arbitrary Host File Read and Write
Nov 7, 2025