Sploitus

CVE-2024-33522

No indexed exploits for CVE-2024-33522 yet

In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Calico Cloud (v19.2.0 and below), an attacker who has local access to the Kubernetes node, can escalate their privileges by exploiting a vulnerability in the Calico CNI install binary. The issue arises from an incorrect SUID (Set User ID) bit configuration in the binary, combined with the ability to control the input binary, allowing an attacker to execute an arbitrary binary with elevated privileges.

Fix
Available
CVSS 3.1
6.7 MEDIUM
EPSS
0.2% (13th percentile)
Weakness
CWE-269
NVD status
Deferred
Published
2024-04-29
Attack patterns
CAPEC-233
CVE-2024-33522 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-33522 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-33522 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.