A security issue was discovered in Kubernetes where a user
 that can create pods on Windows nodes may be able to escalate to admin 
privileges on those nodes. Kubernetes clusters are only affected if they
 include Windows nodes.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/kubernetes/kubernetes/issues/119595 | Exploit Mitigation Patch Third Party Advisory | 
| https://groups.google.com/g/kubernetes-security-announce/c/JrX4bb7d83E | Technical Description | 
| https://security.netapp.com/advisory/ntap-20231221-0002/ | |
| https://github.com/kubernetes/kubernetes/issues/119595 | Exploit Mitigation Patch Third Party Advisory | 
| https://groups.google.com/g/kubernetes-security-announce/c/JrX4bb7d83E | Technical Description | 
| https://security.netapp.com/advisory/ntap-20231221-0002/ | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    13 Feb 2025, 17:17
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | (en) A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. | 
21 Nov 2024, 08:18
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/kubernetes/kubernetes/issues/119595 - Exploit, Mitigation, Patch, Third Party Advisory | |
| References | () https://groups.google.com/g/kubernetes-security-announce/c/JrX4bb7d83E - Technical Description | |
| References | () https://security.netapp.com/advisory/ntap-20231221-0002/ - | 
21 Dec 2023, 22:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
08 Nov 2023, 18:29
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-20 | |
| CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | |
| References | (MISC) https://groups.google.com/g/kubernetes-security-announce/c/JrX4bb7d83E - Technical Description | |
| References | (MISC) https://github.com/kubernetes/kubernetes/issues/119595 - Exploit, Mitigation, Patch, Third Party Advisory | |
| First Time | Microsoft Kubernetes kubernetes Kubernetes Microsoft windows | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 8.8 | 
31 Oct 2023, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-10-31 21:15
Updated : 2025-02-13 17:17
NVD link : CVE-2023-3955
Mitre link : CVE-2023-3955
CVE.ORG link : CVE-2023-3955
JSON object : View
Products Affected
                kubernetes
- kubernetes
microsoft
- windows
CWE
                
                    
                        
                        CWE-20
                        
            Improper Input Validation
