CVE-2025-2903

An attacker with knowledge of creating user accounts during VM deployment on Google Cloud Platform (GCP) using the OS Login feature, can login via SSH gaining command-line control of the operating system. This allows an attacker to gain access to sensitive data stored on the VM, install malicious software, and disrupt or disable the functionality of the VM.
CVSS

No CVSS.

Configurations

No configuration.

History

17 Apr 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-17 07:15

Updated : 2025-04-17 20:21


NVD link : CVE-2025-2903

Mitre link : CVE-2025-2903

CVE.ORG link : CVE-2025-2903


JSON object : View

Products Affected

No product.

CWE
CWE-267

Privilege Defined With Unsafe Actions

CWE-268

Privilege Chaining