logo

The Kubernetes CVE-2023-3676 Windows command injection vulnerability - exploitation and prevalence

ID: 55bf6c31-db2e-530f-afbc-f0d2e397ba05

STIX ID: report--55bf6c31-db2e-530f-afbc-f0d2e397ba05

Feed Name: Datadog Security Labs

Threat Score
75/100

Date Published: 2023-10-27

Date Updated: 2026-04-27

...
...

This report details CVE-2023-3676, a command-injection flaw in Kubernetes Kubelet on Windows nodes where unsanitized volumeMounts.subPath values are passed to PowerShell, enabling pod-creators to run arbitrary commands as the Kubelet (high-privilege SYSTEM). It lists affected Kubelet versions, provides a working PoC pod manifest and observed PowerShell logs, and recommends patching, admission-controller policies, and logging/process monitoring as mitigations and detection strategies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.