QID 378909
Date Published: 2023-10-04
QID 378909: Docker Desktop Local Privilege Escalation Vulnerability (4120)
Docker is a set of the platform as a service product that uses OS-level virtualization to deliver software in packages called containers.
CVE-2023-0633: Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation vulnerability.
Affected Versions:
Docker Desktop Community Edition before 4.12.0
QID Detection Logic:
Windows: It checks for vulnerable versions of Docker Desktop
Successful exploitation of this vulnerability may allow an less privileged attacker to execute commands or perform action actions with higher privileges.
Solution
Customers are advised to upgrade to Docker Desktop version 4.12.0 or later. Please refer to Docker Desktop Release Notes for version 4.12.0 for further information.
Vendor References
- Docker Desktop Release Notes -
docs.docker.com/desktop/release-notes/#4120
CVEs related to QID 378909
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Docker Desktop Release Notes |
|