Vulnerability CVE-2023-3676: Information

Description

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.

Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Published: Nov. 1, 2023
Modified: Dec. 1, 2023
Error type identifier: CWE-20

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*

      cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*

      cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*

      cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*

      cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*