Red Hat Security Advisory: Red Hat OpenShift for Windows Containers 10.16.2 product release
Red Hat OpenShift for Windows Containers allows you to deploy Windows container workloads running on Windows Server containers.
AI Analysis
Technical Summary
CVE-2024-9042 is an OS command injection vulnerability (CWE-78) affecting Kubernetes Windows nodes in Red Hat OpenShift for Windows Containers versions >=10.16.0 and <10.16.2. The flaw allows an attacker with the ability to query the node's '/logs' endpoint to execute arbitrary commands on the host. This can result in unauthorized code execution, data modification, or denial of service. The vulnerability is tracked under Red Hat advisory RHSA-2025:9136. No patch or effective mitigation currently meets Red Hat's standards for ease of use, deployment, or stability. Detection is possible via audit logs monitoring for suspicious node 'logs' queries.
Potential Impact
An attacker with access to query the '/logs' endpoint on Windows worker nodes can execute arbitrary OS commands with the privileges of the node process. This can lead to unauthorized code execution, data read or modification, and potential disruption of the node. The vulnerability compromises confidentiality and integrity but does not impact availability directly. Since commands execute as the node, malicious actions may appear to originate from legitimate processes.
Mitigation Recommendations
Currently, no official patch or mitigation meeting Red Hat's criteria for this vulnerability is available. Users should monitor cluster audit logs for suspicious queries to the node '/logs' endpoint to detect potential exploitation attempts. Red Hat recommends upgrading to a fixed version once available. For Windows Machine Config Operator upgrades, refer to the official Red Hat documentation. Customers with a Red Hat Technical Account Manager (TAM) can seek direct guidance. Until a fix is released, restricting access to the node logs endpoint and limiting permissions may reduce risk.
Red Hat Security Advisory: Red Hat OpenShift for Windows Containers 10.16.2 product release
Description
Red Hat OpenShift for Windows Containers allows you to deploy Windows container workloads running on Windows Server containers.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2024-9042 is an OS command injection vulnerability (CWE-78) affecting Kubernetes Windows nodes in Red Hat OpenShift for Windows Containers versions >=10.16.0 and <10.16.2. The flaw allows an attacker with the ability to query the node's '/logs' endpoint to execute arbitrary commands on the host. This can result in unauthorized code execution, data modification, or denial of service. The vulnerability is tracked under Red Hat advisory RHSA-2025:9136. No patch or effective mitigation currently meets Red Hat's standards for ease of use, deployment, or stability. Detection is possible via audit logs monitoring for suspicious node 'logs' queries.
Potential Impact
An attacker with access to query the '/logs' endpoint on Windows worker nodes can execute arbitrary OS commands with the privileges of the node process. This can lead to unauthorized code execution, data read or modification, and potential disruption of the node. The vulnerability compromises confidentiality and integrity but does not impact availability directly. Since commands execute as the node, malicious actions may appear to originate from legitimate processes.
Mitigation Recommendations
Currently, no official patch or mitigation meeting Red Hat's criteria for this vulnerability is available. Users should monitor cluster audit logs for suspicious queries to the node '/logs' endpoint to detect potential exploitation attempts. Red Hat recommends upgrading to a fixed version once available. For Windows Machine Config Operator upgrades, refer to the official Red Hat documentation. Customers with a Red Hat Technical Account Manager (TAM) can seek direct guidance. Until a fix is released, restricting access to the node logs endpoint and limiting permissions may reduce risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:9136
- Cve Count
- 3
- Additional Cves
- ["CVE-2024-45338","CVE-2025-22869"]
Threat ID: 6a160978e29bf47b50644ae6
Added to database: 05/26/2026, 20:58:32 UTC
Last enriched: 08/10/2026, 18:04:59 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 62
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.