First published: Mon Sep 25 2023(Updated: )
In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation (LPE).This issue affects Docker Desktop: before 4.12.0.
Credit: security@docker.com
Affected Software | Affected Version | How to fix |
---|---|---|
Docker Desktop | <4.12.0 |
Update to 4.12.0
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0633 is a vulnerability in Docker Desktop on Windows that allows for argument injection to the installer, resulting in local privilege escalation (LPE).
Docker Desktop versions before 4.12.0 are affected by CVE-2023-0633.
CVE-2023-0633 has a severity rating of 7.2 (high).
To fix CVE-2023-0633, update Docker Desktop to version 4.12.0 or later.
More information about CVE-2023-0633 can be found in the Docker Desktop release notes: [link](https://docs.docker.com/desktop/release-notes/#4120).