CVE-2021-1677
CVE-2021-1677 is a medium-severity vulnerability in Microsoft Azure Kubernetes Service with a CVSS 3.x base score of 5.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-290.
Key facts
- Severity: Medium (CVSS 3.x base score 5.5)
- CVSS v2: 2.1
- EPSS exploit prediction: 1% (64th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-290
- Affected product: Microsoft Azure Kubernetes Service
- Published:
- Last modified:
Description
Azure Active Directory Pod Identity Spoofing Vulnerability
Frequently asked questions
- What is CVE-2021-1677?
- Azure Active Directory Pod Identity Spoofing Vulnerability
- How severe is CVE-2021-1677?
- CVE-2021-1677 has a CVSS 3.x base score of 5.5, rated medium severity. It is exploitable over local access with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2021-1677 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (64th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-1677?
- CVE-2021-1677 affects Microsoft Azure Kubernetes Service. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2021-1677?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2021-1677 published?
- CVE-2021-1677 was published on 2021-01-12 and last updated on 2026-06-17.
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-1677
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1677
Affected products (1)
- cpe:2.3:a:microsoft:azure_kubernetes_service:-:*:*:*:*:*:*:*
More vulnerabilities in Microsoft Azure Kubernetes Service
- CVE-2026-56163 — Critical (CVSS 10.0): Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to…
- CVE-2026-33105 — Critical (CVSS 10.0): Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over…
- CVE-2026-50516 — Critical (CVSS 9.4): Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to…
- CVE-2024-21403 — Critical (CVSS 9.0): Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
- CVE-2024-21376 — Critical (CVSS 9.0): Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
- CVE-2026-32193 — High (CVSS 8.8): Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service…
All CVEs affecting Microsoft Azure Kubernetes Service →
Other CWE-290 vulnerabilities
- CVE-2026-54782 — Critical (CVSS 10.0): CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,…
- CVE-2026-48567 — Critical (CVSS 10.0): Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a…
- CVE-2026-6213 — Critical (CVSS 10.0): A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check…
- CVE-2026-39858 — Critical (CVSS 10.0): Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high…
- CVE-2025-66570 — Critical (CVSS 10.0): cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability…
- CVE-2025-34063 — Critical (CVSS 10.0): A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure…