← Back

CVE-2023-3676

nvd nist
Published: Oct 31, 2023Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.

Affected (5)

1 product
Kubernetes
Configuration A
5 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Kubernetes
Before 1.24.17
From 1.25.0 to 1.25.13
From 1.26.0 to 1.26.8
From 1.27.0 to 1.27.5
From 1.28.0 to 1.28.1
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (6)

Source: jordan@liggitt.net
ExploitMitigationPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.