Patch Now: Kubernetes RCE Flaw Allows Full Takeover of Windows Nodes
ID: 1e223629-01ea-548a-8514-254d087ecdc1
STIX ID: report--1e223629-01ea-548a-8514-254d087ecdc1
Feed Name: Dark Reading
Date Published: 2024-03-13
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
The report details CVE-2023-5528, a command-injection vulnerability in Kubernetes' handling of local volumes on Windows nodes that can be exploited by submitting crafted YAML (pods and persistent volumes) to achieve SYSTEM-level remote code execution; discovered by Akamai researcher Tomer Peled with a proof-of-concept, the flaw affects Kubernetes versions earlier than 1.28.4 (including AKS deployments using Windows nodes), has a CVSS of 7.2, and is mitigated by a patch that replaces a cmd exec call with a safe Go symlink operation and by following best practices (patching, RBAC, and provided OPA detection rules).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
