CVE-2023-3955 is a high-severity privilege escalation vulnerability (CVSS 8.8) affecting Kubernetes clusters with Windows nodes. An authenticated user with pod creation privileges on Windows nodes can escalate to administrative access on those nodes. While no public exploits or active exploitation have been confirmed, the vulnerability has garnered significant community discussion and media coverage, indicating heightened awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.24.17CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | ||
>= 1.25.0, < 1.25.13CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | ||
>= 1.26.0, < 1.26.8CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | ||
>= 1.27.0, < 1.27.5CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | ||
>= 1.28.0, < 1.28.1CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Kubernetes privilege escalation vulnerability
Oct 31, 2023kubernetes: Insufficient input sanitization on Windows nodes leads to privilege escalation
Aug 23, 2023Insufficient input sanitization on Windows nodes leads to privilege escalation
Insufficient input sanitization on Windows nodes leads to privilege escalation
Insufficient input sanitization on Windows nodes leads to privilege escalation
Insufficient input sanitization on Windows nodes leads to privilege escalation