CVE-2024-33522 - CVE House
Back to Database
Status published Medium CVE-2024-33522

Privilege escalation in Calico CNI install binary

Vulnerability Description

In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Calico Cloud (v19.2.0 and below), an attacker who has local access to the Kubernetes node, can escalate their privileges by exploiting a vulnerability in the Calico CNI install binary. The issue arises from an incorrect SUID (Set User ID) bit configuration in the binary, combined with the ability to control the input binary, allowing an attacker to execute an arbitrary binary with elevated privileges.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-33522

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Christopher Alonso (Github: @latortuga71)
  • Anthony Tam
  • Behnam Shobiri
  • Pedro Coutinho
  • Matt Dupre

Affected Vendor

Affected Software

Calico, Calico Enterprise , Calico Cloud
Vulnerable Versions:
0, v3.27.0, v3.28.0, v3.18.0, v3.19.0-1.0

Timeline

Official Publish: April 29th, 2024
Last Modified: August 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)