CVE-2023-3676

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Oct 31, 2023
Updated: Nov 30, 2023
CWE ID 20

Summary

CVE-2023-3676 is a new vulnerability affecting Kubernetes clusters that include Windows nodes. This issue grants users with the ability to create pods on these nodes the potential to escalate their privileges to admin level. If exploited, an attacker could take control of the Windows nodes in the cluster and cause significant damage. The full impact of this vulnerability is still under investigation, but it is recommended that organizations using Kubernetes with Windows nodes apply updates or patches as soon as they become available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Office Word
  • Microsoft Office
  • Microsoft 365 Apps

Affected Vendors

  • Microsoft