CVE-2025-2312

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 502

Summary

CVE-2025-2312 is a vulnerability affecting the cifs-utils package. In containerized environments, the cifs.upcall program fails to correctly identify the namespace, causing it to access the wrong namespace instead. This error results in the disclosure of sensitive data from the host's Kerberos credentials cache. Attackers could potentially exploit this issue to gain unauthorized access to protected systems or steal confidential information. It is recommended that users update their cifs-utils packages to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Veeam Backup & Replication

Affected Vendors

  • Veeam