logo

Patch Now: Kubernetes RCE Flaw Allows Full Takeover of Windows Nodes

ID: 1e223629-01ea-548a-8514-254d087ecdc1

STIX ID: report--1e223629-01ea-548a-8514-254d087ecdc1

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-03-13

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

The report details CVE-2023-5528, a command-injection vulnerability in Kubernetes' handling of local volumes on Windows nodes that can be exploited by submitting crafted YAML (pods and persistent volumes) to achieve SYSTEM-level remote code execution; discovered by Akamai researcher Tomer Peled with a proof-of-concept, the flaw affects Kubernetes versions earlier than 1.28.4 (including AKS deployments using Windows nodes), has a CVSS of 7.2, and is mitigated by a patch that replaces a cmd exec call with a safe Go symlink operation and by following best practices (patching, RBAC, and provided OPA detection rules).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.