Impact
The vulnerability arises from a protection mechanism failure in the Cluster Management Toolkit for Kubernetes before version v0.8.5. This flaw allows a system software adversary with privileged user access to elevate privileges within Ring 3. An attacker can potentially gain full control over the managed cluster through a low‑complexity local attack that requires passive user interaction but no special internal knowledge. The impact would be severe, compromising confidentiality, integrity, and availability of the vulnerable system, while downstream services would experience no further loss.
Affected Systems
Affected systems are deployments of the Cluster Management Toolkit for Kubernetes running any version earlier than v0.8.5. No specific vendor name is provided by the CNA, but the problematic product is the toolkit itself.
Risk and Exploitability
The CVSS score of 5.4 classifies this incident as moderately dangerous, and the EPSS score of less than 1% indicates a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers would require local access and privileged user rights; because the exploitation complexity is low and no special knowledge is needed, an internal adversary could achieve privilege escalation if they control an account with administrative privileges.
OpenCVE Enrichment