CVE-2025-64436
Microsoft · Published December 7, 2025
5.3
CVSS v3.1
MEDIUMPatch availableGet patch
Description
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes. KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Affected Products
- cbl2 kubevirt 0.59.0-30 on CBL Mariner 2.0
- cbl2 kubevirt 0.59.0-31 on CBL Mariner 2.0
- azl3 kubevirt 1.5.3-2 on Azure Linux 3.0
- cbl2 kubevirt 0.59.0-35 on CBL Mariner 2.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N