CVE-2023-3955: Kubernetes - Windows nodes - Insufficient input sanitization leads to privilege escalation
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-3955?
CVE-2023-3955 is a vulnerability in Kubernetes that allows a user on Windows nodes to escalate privileges to admin.
What is the severity of CVE-2023-3955?
The severity of CVE-2023-3955 is high with a CVSS score of 8.8.
How does CVE-2023-3955 affect Kubernetes clusters?
CVE-2023-3955 affects Kubernetes clusters that include Windows nodes.
How can I fix CVE-2023-3955?
To fix CVE-2023-3955, you need to update Kubernetes to version 1.24.17, 1.25.13, 1.26.8, 1.27.5, or 1.28.1.
Where can I find more information about CVE-2023-3955?
You can find more information about CVE-2023-3955 on Red Hat's website at the following URLs: [https://access.redhat.com/errata/RHSA-2023:4777](https://access.redhat.com/errata/RHSA-2023:4777), [https://access.redhat.com/errata/RHSA-2023:4780](https://access.redhat.com/errata/RHSA-2023:4780), [https://access.redhat.com/errata/RHSA-2023:4835](https://access.redhat.com/errata/RHSA-2023:4835).