← All CVEs

CVE-2023-3676

high · 8.8

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.

8.8
CVSS
13.2%
EPSS (exploit prob.)
96th
EPSS percentile
2023-10-31
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
kuberneteskubernetes< 1.24.17
kuberneteskubernetes>= 1.25.0, < 1.25.13
kuberneteskubernetes>= 1.26.0, < 1.26.8
kuberneteskubernetes>= 1.27.0, < 1.27.5
kuberneteskubernetes>= 1.28.0, < 1.28.1
microsoftwindowsall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-3676