← Back

CVE-2023-5528

nvd nist
Published: Nov 14, 2023Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they are using an in-tree storage plugin for Windows nodes.

Affected (7)

1 product
Kubernetes
1 product
Fedora
Configuration A
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Kubernetes
From 1.26.0 to 1.26.11
From 1.27.0 to 1.27.8
From 1.28.0 to 1.28.4
From 1.8.0 to 1.25.16
Running on/withPlatform Versions
Microsoft
Windows
All versions
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 37
Version 38
Version 39

References (8)

Timeline

No history available yet.