Vulnerability record · CVE-2018-1000400 · published 18 May 2018
CVE-2018-1000400: Kubernetes cri-o improper privilege management vulnerability
Kubernetes · Cri O
Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers running with elevated privileges, allowing users abilities they should not have. This attack appears to be exploitable via container execution. This vulnerability appears to have been fixed in 1.9.
Description
Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers running with elevated privileges, allowing users abilities they should not have. This attack appears to be exploitable via container execution. This vulnerability appears to have been fixed in 1.9.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/104262 | Third Party AdvisoryVDB Entry |
| https://github.com/kubernetes-incubator/cri-o/pull/1558/files | PatchThird Party Advisory |
| http://www.securityfocus.com/bid/104262 | Third Party AdvisoryVDB Entry |
| https://github.com/kubernetes-incubator/cri-o/pull/1558/files | PatchThird Party Advisory |
Track CVE-2018-1000400 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-1000400), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.