PT-2025-45439 · Kubevirt+1 · Kubevirt+1

CVE-2025-64436

·

Published

2025-11-06

·

Updated

2026-07-30

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions KubeVirt versions prior to 1.5.0
Description KubeVirt, a virtual machine management add-on for Kubernetes, has an issue where permissions granted to the virt-handler service account could be misused. Specifically, the ability to update VMIs and patch nodes could be exploited to force a VMI migration to a node controlled by an attacker. This could allow an attacker to mark all nodes as unschedulable, potentially leading to the migration or creation of privileged pods onto a compromised node.
Recommendations Update to a version of KubeVirt greater than or equal to 1.5.0.

Exploit

Fix

Incorrect Default Permissions

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-69790
AZL-69967
CVE-2025-64436
GHSA-7XGM-5PRM-V5GC
GO-2025-4104
OPENSUSE-SU-2026:21483-1

Affected Products

Kubevirt
Kubernetes