Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by controlling the pidfile field inside the DaemonJSON field in the WindowsContainerStartRequest class. This can indirectly lead to privilege escalation.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-04-27T00:00:00
Updated: 2024-08-03T10:29:20.897Z
Reserved: 2022-08-01T00:00:00
Link: CVE-2022-37326
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2023-04-27T20:15:40.113
Modified: 2023-05-09T15:13:27.597
Link: CVE-2022-37326
Redhat
No data.