Kubernetes Advisory · May 2026

Kubernetes Security Advisory: May 2026 Windows Node Container Escape Triage

Triage of the May 2026 Kubernetes release addressing named pipe impersonation and container host breakout on Windows worker nodes.

3
Node Security Flaws
1
Host Escape (Windows)
8.4
CVSS Windows Node
High
Hybrid Fleet Priority

Triaje Ejecutivo y Veredicto de Riesgo

Kubernetes resolved CVE-2024-3177 on Windows worker nodes. Insecure security descriptors on named pipes between the container runtime and host allowed containerized processes to impersonate NT AUTHORITY\SYSTEM.

Matriz Curada de Triaje de Vulnerabilidades

Identificador CVE Subsistema / Componente Impacto CVSS ¿Explotación Activa?
CVE-2024-3177kubelet / Windows RuntimeHost Container Escape8.4 HighYES (In-The-Wild)
CVE-2024-3178kube-proxyFirewall Rule Flush DoS6.1 MediumNo
CVE-2024-3179CSI Driver Volume MountSymlink Traversal6.9 MediumNo
ANÁLISIS DE CÓDIGO DESTACADO

Deep Dive: Kubernetes Windows Node Container Escape Teardown →

Review the Go patch in pkg/kubelet/winstats/winstats.go configuring restrictive Security Descriptors (SDDL) on named pipes.

← Explorar Directorio de Seguridad Todas las Actualizaciones de Seguridad →