CVE-2022-26659: High severity docker desktop vulnerability
Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop installer, when run elevated, will write its log files to a location not writable by non-administrator users.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26659?
CVE-2022-26659 is a vulnerability in Docker Desktop installer on Windows versions before 4.6.0 that allows an attacker to overwrite administrator writable files.
How can an attacker exploit CVE-2022-26659?
An attacker can exploit CVE-2022-26659 by creating a symlink in place of the installer's log file, which allows them to overwrite administrator writable files.
What is the severity of CVE-2022-26659?
The severity of CVE-2022-26659 is high, with a CVSS score of 7.1.
Which versions of Docker Desktop on Windows are affected?
Docker Desktop versions before 4.6.0 on Windows are affected by CVE-2022-26659.
How do I fix CVE-2022-26659?
To fix CVE-2022-26659, update Docker Desktop to version 4.6.0 or later.