CVE-2022-25365: High severity Docker docker vulnerability
Published Feb 19, 2022
·Updated
Docker Desktop before 4.5.1 on Windows allows attackers to move arbitrary files. NOTE: this issue exists because of an incomplete fix for CVE-2022-23774.
Affected Software
2 affected components
Docker docker<4.5.1
Microsoft Windows
Remediation
Patch Available
Event History
Feb 19, 2022
CVE Published
via MITRE·01:56 AM
Data Sourced
via MITRE·01:56 AM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-25365?
CVE-2022-25365 is a vulnerability in Docker Desktop before 4.5.1 on Windows that allows attackers to move arbitrary files.
2
How does CVE-2022-25365 affect Docker Desktop on Windows?
CVE-2022-25365 affects Docker Desktop on Windows by allowing attackers to move arbitrary files.
3
What is the severity of CVE-2022-25365?
The severity of CVE-2022-25365 is high with a CVSSv3 score of 7.8.
4
How can I fix CVE-2022-25365?
To fix CVE-2022-25365, you should update Docker Desktop to version 4.5.1 or later.
5
Where can I find more information about CVE-2022-25365?
You can find more information about CVE-2022-25365 in the release notes of Docker Desktop for Windows.