CVE-2025-2713

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 28, 2025
CWE ID 89

Summary

CVE-2025-2713 is a local privilege escalation vulnerability affecting Google's gVisor runsc component. The issue arises from the incorrect handling of file access permissions, allowing unprivileged users to gain access to restricted files. Initially, the process runs with root-like permissions, making it vulnerable to this exploit during the first fork. This flaw poses a significant risk and highlights the importance of proper file access management in containerized environments.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share