Triage of the May 2026 Kubernetes release addressing named pipe impersonation and container host breakout on Windows worker nodes.
NT AUTHORITY\SYSTEM.
| Pengenal CVE | Subsistem / Komponen | Dampak | CVSS | Eksploitasi Aktif? |
|---|---|---|---|---|
| CVE-2024-3177 | kubelet / Windows Runtime | Host Container Escape | 8.4 High | YES (In-The-Wild) |
| CVE-2024-3178 | kube-proxy | Firewall Rule Flush DoS | 6.1 Medium | No |
| CVE-2024-3179 | CSI Driver Volume Mount | Symlink Traversal | 6.9 Medium | No |
Review the Go patch in pkg/kubelet/winstats/winstats.go configuring restrictive Security Descriptors (SDDL) on named pipes.