CVE-2025-64434

MEDIUM

kubevirt < 1.5.3 - Improper Authentication via Shared Credentials

Title source: llm
STIX 2.1

Description

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification logic in virt-handler (via verifyPeerCert), an attacker who compromises a virt-handler instance, could exploit these shared credentials to impersonate virt-api and execute privileged operations against other virt-handler instances potentially compromising the integrity and availability of the VM managed by it. This vulnerability is fixed in 1.5.3 and 1.6.1.

Scores

CVSS v3 4.7
EPSS 0.0016
EPSS Percentile 5.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (3)
kubevirt/kubevirt 1.6.0
kubevirt/kubevirt < 1.5.3
kubevirt.io/kubevirt 0 - 1.5.3Go
Published Nov 07, 2025
Tracked Since Feb 18, 2026