The Kubernetes CVE-2023-3676 Windows command injection vulnerability - exploitation and prevalence
ID: 55bf6c31-db2e-530f-afbc-f0d2e397ba05
STIX ID: report--55bf6c31-db2e-530f-afbc-f0d2e397ba05
Feed Name: Datadog Security Labs
This report details CVE-2023-3676, a command-injection flaw in Kubernetes Kubelet on Windows nodes where unsanitized volumeMounts.subPath values are passed to PowerShell, enabling pod-creators to run arbitrary commands as the Kubelet (high-privilege SYSTEM). It lists affected Kubelet versions, provides a working PoC pod manifest and observed PowerShell logs, and recommends patching, admission-controller policies, and logging/process monitoring as mitigations and detection strategies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
