QID 379076

Date Published: 2023-12-05

QID 379076: Docker Desktop Community Local Privilege Escalation Vulnerability

Docker is a set of platform as a service products that uses OS-level virtualization to deliver software in packages called containers.

CVE-2020-15360: com.docker.vmnetd in Docker Desktop allows privilege escalation because of a lack of client verification.

Affected Versions:
Docker Desktop Community Edition in version 2.3.0.3

QID Detection Logic:
It checks for vulnerable version of Docker.

Successful exploitation of this vulnerability can lead to privilege escalation because of a lack of client verification.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Customers are advised to upgrade to latest Docker Desktop version. Please refer to Docker Desktop for further information.
    Vendor References

    CVEs related to QID 379076

    Software Advisories
    Advisory ID Software Component Link
    Docker Desktop URL Logo docs.docker.com/docker-for-windows/release-notes/