// For flags

CVE-2024-33522

Privilege escalation in Calico CNI install binary

Severity Score

6.7
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track*
*SSVC
Descriptions

In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Calico Cloud (v19.2.0 and below), an attacker who has local access to the Kubernetes node, can escalate their privileges by exploiting a vulnerability in the Calico CNI install binary. The issue arises from an incorrect SUID (Set User ID) bit configuration in the binary, combined with the ability to control the input binary, allowing an attacker to execute an arbitrary binary with elevated privileges.

En versiones vulnerables de Calico (v3.27.2 e inferiores), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 e inferiores) y Calico Cloud (v19.2.0 e inferiores), un atacante que tiene acceso local al nodo de Kubernetes, pueden escalar sus privilegios explotando una vulnerabilidad en el binario de instalaciĆ³n de Calico CNI. El problema surge de una configuraciĆ³n incorrecta del bit SUID (Establecer ID de usuario) en el binario, combinada con la capacidad de controlar el binario de entrada, lo que permite a un atacante ejecutar un binario arbitrario con privilegios elevados.

*Credits: Christopher Alonso (Github: @latortuga71), Anthony Tam, Behnam Shobiri, Pedro Coutinho, Matt Dupre
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2024-04-23 CVE Reserved
  • 2024-04-29 CVE Published
  • 2024-04-30 EPSS Updated
  • 2024-08-02 CVE Updated
  • 2024-08-02 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-269: Improper Privilege Management
CAPEC
  • CAPEC-233: Privilege Escalation
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Tigera
Search vendor "Tigera"
Calico
Search vendor "Tigera" for product "Calico"
< v3.26.5
Search vendor "Tigera" for product "Calico" and version " < v3.26.5"
en
Affected
Tigera
Search vendor "Tigera"
Calico
Search vendor "Tigera" for product "Calico"
>= v3.27.0 < v3.27.3
Search vendor "Tigera" for product "Calico" and version " >= v3.27.0 < v3.27.3"
en
Affected
Tigera
Search vendor "Tigera"
Calico Enterprise
Search vendor "Tigera" for product "Calico Enterprise"
< v3.17.4
Search vendor "Tigera" for product "Calico Enterprise" and version " < v3.17.4"
en
Affected
Tigera
Search vendor "Tigera"
Calico Enterprise
Search vendor "Tigera" for product "Calico Enterprise"
>= v3.18.0 < v3.18.2
Search vendor "Tigera" for product "Calico Enterprise" and version " >= v3.18.0 < v3.18.2"
en
Affected
Tigera
Search vendor "Tigera"
Calico Enterprise
Search vendor "Tigera" for product "Calico Enterprise"
>= v3.19.0-1.0 < v3.19.0-2.0
Search vendor "Tigera" for product "Calico Enterprise" and version " >= v3.19.0-1.0 < v3.19.0-2.0"
en
Affected
Tigera
Search vendor "Tigera"
Calico Cloud
Search vendor "Tigera" for product "Calico Cloud"
< v19.3.0
Search vendor "Tigera" for product "Calico Cloud" and version " < v19.3.0"
en
Affected