CVE-2025-2241
CVSS 3.1 Score 8.2 of 10 (high)
Details
Published Mar 17, 2025
CWE ID 922
Summary
CVE-2025-2241 is a newly discovered vulnerability affecting Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This flaw exposes VCenter credentials in the ClusterProvision object following the provisioning of a VSphere cluster. Read access to ClusterProvision objects is sufficient for attackers to extract sensitive credentials, even without direct access to Kubernetes Secrets. The consequences of this vulnerability include unauthorized access to VCenter, cluster management, and potential privilege escalation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.