Don't want your Kubernetes Windows nodes hijacked? Patch this hole now
ID: 89522d51-b899-575f-98f7-a113981b3f46
STIX ID: report--89522d51-b899-575f-98f7-a113981b3f46
Feed Name: The Register (Security)
A now-fixed command-injection vulnerability (CVE-2024-9042) in Kubernetes' beta Log Query feature can be abused to execute commands as SYSTEM on Windows nodes by supplying a malicious "pattern" parameter; it affects Kubernetes versions earlier than 1.32.1 with beta features enabled, has a CVSS-like medium score (5.9), a published proof-of-concept Curl invocation, and although Akamai reported no observed active exploitation, maintainers advise patching due to the potential impact and ease of payload creation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
