First published: Fri Mar 25 2022(Updated: )
Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop installer, when run elevated, will write its log files to a location not writable by non-administrator users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Docker Desktop | <4.6.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-26659 is a vulnerability in Docker Desktop installer on Windows versions before 4.6.0 that allows an attacker to overwrite administrator writable files.
An attacker can exploit CVE-2022-26659 by creating a symlink in place of the installer's log file, which allows them to overwrite administrator writable files.
The severity of CVE-2022-26659 is high, with a CVSS score of 7.1.
Docker Desktop versions before 4.6.0 on Windows are affected by CVE-2022-26659.
To fix CVE-2022-26659, update Docker Desktop to version 4.6.0 or later.