QID 378909

Date Published: 2023-10-04

QID 378909: Docker Desktop Local Privilege Escalation Vulnerability (4120)

Docker is a set of the platform as a service product that uses OS-level virtualization to deliver software in packages called containers.

CVE-2023-0633: Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation vulnerability.

Affected Versions:
Docker Desktop Community Edition before 4.12.0

QID Detection Logic:
Windows: It checks for vulnerable versions of Docker Desktop

Successful exploitation of this vulnerability may allow an less privileged attacker to execute commands or perform action actions with higher privileges.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to upgrade to Docker Desktop version 4.12.0 or later. Please refer to Docker Desktop Release Notes for version 4.12.0 for further information.
    Vendor References

    CVEs related to QID 378909

    Software Advisories
    Advisory ID Software Component Link
    Docker Desktop Release Notes URL Logo docs.docker.com/desktop/release-notes/#4120