CVE-2023-0627: Docker Desktop 4.11.x allows --no-windows-containers flag bypass
Published Sep 25, 2023
·Updated
Docker Desktop 4.11.x allows --no-windows-containers flag bypass via IPC response spoofing which may lead to Local Privilege Escalation (LPE).This issue affects Docker Desktop: 4.11.X.
Affected Software
1 affected component
Docker Docker Desktop>=4.11.0<4.12.0
Remediation
Information
Update to 4.12.0
Event History
Sep 25, 2023
CVE Published
via MITRE·03:31 PM
Data Sourced
via MITRE·03:31 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Docker Desktop issue?
The vulnerability ID for this Docker Desktop issue is CVE-2023-0627.
2
What is the severity level of Docker Desktop vulnerability CVE-2023-0627?
The severity level of Docker Desktop vulnerability CVE-2023-0627 is high.
3
What is the impact of Docker Desktop vulnerability CVE-2023-0627?
Docker Desktop vulnerability CVE-2023-0627 may lead to Local Privilege Escalation (LPE).
4
How can the Docker Desktop vulnerability CVE-2023-0627 be exploited?
Docker Desktop vulnerability CVE-2023-0627 can be exploited through IPC response spoofing to bypass the --no-windows-containers flag.
5
How can I fix the Docker Desktop vulnerability CVE-2023-0627?
To fix the Docker Desktop vulnerability CVE-2023-0627, update to version 4.12.0 or higher.