Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-64434

Опубликовано: 07 нояб. 2025
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification logic in virt-handler (via verifyPeerCert), an attacker who compromises a virt-handler instance, could exploit these shared credentials to impersonate virt-api and execute privileged operations against other virt-handler instances potentially compromising the integrity and availability of the VM managed by it. This vulnerability is fixed in 1.5.3 and 1.6.1.

A flaw was found in KubeVirt's virt-handler component. Improper TLS certificate verification in the peer authentication logic allows an attacker who has compromised one virt-handler instance to impersonate the virt-api component and execute privileged operations against other virt-handler instances, compromising the integrity and availability of virtual machines managed across the cluster.

Отчет

The impact oF this vulnerability is rated MODERATE because successful exploitation requires first compromising a privileged virt-handler component, which is not directly accessible to untrusted users and requires prior breach of Kubernetes node or container security boundaries. he vulnerability stems from shared credentials and inadequate validation that allows a compromised virt-handler to present itself as the legitimate virt-api service when communicating with other virt-handler instances. An attacker who successfully compromises a single virt-handler - a privileged Kubernetes DaemonSet component running on each node, can exploit this authentication weakness to perform lateral movement within the cluster, executing privileged operations on VMs managed by other virt-handler instances on different nodes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Virtualization 4kubevirtFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2413483kubevirt: KubeVirt: API Identity Spoofing Vulnerability

EPSS

Процентиль: 5%
0.0002
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
nvd
5 месяцев назад

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification logic in virt-handler (via verifyPeerCert), an attacker who compromises a virt-handler instance, could exploit these shared credentials to impersonate virt-api and execute privileged operations against other virt-handler instances potentially compromising the integrity and availability of the VM managed by it. This vulnerability is fixed in 1.5.3 and 1.6.1.

CVSS3: 4.7
msrc
4 месяца назад

KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing

CVSS3: 4.7
github
5 месяцев назад

KubeVirt's Improper TLS Certificate Management Handling Allows API Identity Spoofing

suse-cvrf
4 месяца назад

Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container

suse-cvrf
около 1 месяца назад

Security update for kubevirt

EPSS

Процентиль: 5%
0.0002
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2025-64434