A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the Windows image build process when using the Nutanix or VMware OVA providers. These credentials, which allow root access, are disabled at the conclusion of the build. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project and the vulnerability was exploited during the build process, which requires an attacker to access the build VM and modify the image while the build is in progress.
Metrics
Affected Vendors & Products
References
History
Wed, 20 Aug 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the image build process. Additionally, virtual machine images built using the Nutanix or the OVA provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their Windows nodes use VM images created via the Image Builder project with its Nutanix or OVA provider. | A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the Windows image build process when using the Nutanix or VMware OVA providers. These credentials, which allow root access, are disabled at the conclusion of the build. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project and the vulnerability was exploited during the build process, which requires an attacker to access the build VM and modify the image while the build is in progress. |
Mon, 18 Aug 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Kubernetes
Kubernetes image Builder |
|
Vendors & Products |
Kubernetes
Kubernetes image Builder |
Mon, 18 Aug 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sun, 17 Aug 2025 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the image build process. Additionally, virtual machine images built using the Nutanix or the OVA provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their Windows nodes use VM images created via the Image Builder project with its Nutanix or OVA provider. | |
Title | VM images built with Kubernetes Image Builder Nutanix or OVA providers use default credentials for Windows images if user did not override | |
Weaknesses | CWE-798 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: kubernetes
Published: 2025-08-17T23:03:56.571Z
Updated: 2025-08-20T00:47:11.031Z
Reserved: 2025-07-07T22:31:53.942Z
Link: CVE-2025-7342

Updated: 2025-08-18T17:30:34.691Z

Status : Awaiting Analysis
Published: 2025-08-17T23:15:26.860
Modified: 2025-08-20T01:15:31.027
Link: CVE-2025-7342

No data.