CVE-2025-2241

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Mar 17, 2025
CWE ID 922

Summary

CVE-2025-2241 is a newly discovered vulnerability affecting Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This flaw exposes VCenter credentials in the ClusterProvision object following the provisioning of a VSphere cluster. Read access to ClusterProvision objects is sufficient for attackers to extract sensitive credentials, even without direct access to Kubernetes Secrets. The consequences of this vulnerability include unauthorized access to VCenter, cluster management, and potential privilege escalation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share