CVE-2020-15360: High severity docker desktop vulnerability
Published Jun 27, 2020
·Updated
com.docker.vmnetd in Docker Desktop 2.3.0.3 allows privilege escalation because of a lack of client verification.
Affected Software
1 affected component
Docker Docker Desktop=2.3.0.3
Event History
Jun 27, 2020
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-15360?
The severity of CVE-2020-15360 is high with a CVSS score of 7.8.
2
How does CVE-2020-15360 allow privilege escalation?
CVE-2020-15360 allows privilege escalation due to a lack of client verification in com.docker.vmnetd in Docker Desktop 2.3.0.3.
3
What software is affected by CVE-2020-15360?
Docker Desktop 2.3.0.3 is affected by CVE-2020-15360.
4
How can I fix CVE-2020-15360?
To fix CVE-2020-15360, it is recommended to update Docker Desktop to a version that includes the necessary security patches.
5
Where can I find more information about CVE-2020-15360?
You can find more information about CVE-2020-15360 in the Docker Desktop release notes and a blog post detailing the privilege escalation vulnerability.