CVE-2024-5652: In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker daemon config option in Windows containers mode
In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker daemon config option in Windows containers mode.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Docker Desktop (Windows)to a version that resolves this vulnerability.Fixed in 4.31.0 - Compensating control
Until upgraded, restrict membership in the docker-users group so untrusted users cannot access Docker Desktop (Windows containers mode), reducing the risk of exploitation via the exec-path Docker daemon config option.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5652?
CVE-2024-5652 is classified as a Denial-of-Service vulnerability.
How do I fix CVE-2024-5652?
To mitigate CVE-2024-5652, update Docker Desktop to version 4.31.0 or later.
What does CVE-2024-5652 affect?
CVE-2024-5652 affects Docker Desktop for Windows prior to version 4.31.0.
Who is affected by CVE-2024-5652?
Users in the docker-users group may be affected by CVE-2024-5652.
What is the impact of CVE-2024-5652?
The impact of CVE-2024-5652 is a potential Denial-of-Service condition in Windows containers.