Description
Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by controlling the pidfile field inside the DaemonJSON field in the WindowsContainerStartRequest class. This can indirectly lead to privilege escalation.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-39961 | Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by controlling the pidfile field inside the DaemonJSON field in the WindowsContainerStartRequest class. This can indirectly lead to privilege escalation. |
References
History
Fri, 31 Jan 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-31T19:12:59.334Z
Reserved: 2022-08-01T00:00:00.000Z
Link: CVE-2022-37326
Updated: 2024-08-03T10:29:20.897Z
Status : Modified
Published: 2023-04-27T20:15:40.113
Modified: 2025-01-31T20:15:29.257
Link: CVE-2022-37326
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD