Executive brief
Intel's Cluster Management Toolkit for Kubernetes contains a protection mechanism failure that could allow privilege escalation on affected systems. The vulnerability requires local access and a privileged user, but if exploited could compromise system confidentiality, integrity, and availability. Intel has discontinued support for this product and recommends all users uninstall or discontinue use immediately.
Technical details
The vulnerability is a protection mechanism failure in Ring 3 (User Applications) of Intel's Cluster Management Toolkit for Kubernetes before version v0.8.5. It allows escalation of privilege via local access when a privileged user is present and passive user interaction occurs. The attack requires a system software adversary context with low complexity. The vulnerability impacts system confidentiality, integrity, and availability. Intel has discontinued the product and will not issue patches; affected users must uninstall or discontinue use.
Affected products
- Intel Cluster Management Toolkit for Kubernetes before v0.8.5
Timeline
- 2026-08-11: disclosed
- 2026-08-11: advisory: Intel INTEL-SA-01460 advisory published; Product Discontinuation Notice issued