QID 378910
Date Published: 2023-10-04
QID 378910: Docker Desktop Local Privilege Escalation Vulnerability (4120)
Docker is a set of the platform as a service product that uses OS-level virtualization to deliver software in packages called containers.
CVE-2023-0627: Docker Desktop 4.11.x allows --no-windows-containers flag bypass via IPC response spoofing which may lead to local privilege escalation vulnerability.
Affected Versions:
Docker Desktop Community Edition versions from 4.11.0 prior to 4.12.0
QID Detection Logic:
Windows: It checks for vulnerable versions of Docker Desktop
Successful exploitation of this vulnerability may allow an less privileged attacker to execute commands or perform action actions with higher privileges.
Solution
Customers are advised to upgrade to Docker Desktop version 4.12.0 or later. Please refer to Docker Desktop Release Notes for version 4.12.0 for further information.
Vendor References
- Docker Desktop Release Notes -
docs.docker.com/desktop/release-notes/#4120
CVEs related to QID 378910
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Docker Desktop Release Notes |
|