CVE-2024-8695: A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2.
Published Sep 12, 2024
·Updated
A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2.
Affected Software
1 affected component
Docker Desktop<4.34.2
Remediation
Information
Update Docker Desktop to 4.34.2 or a later version
Event History
Sep 12, 2024
CVE Published
via MITRE·05:52 PM
Data Sourced
via MITRE·05:52 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-8695?
CVE-2024-8695 is classified as a high severity remote code execution vulnerability.
2
How do I fix CVE-2024-8695?
To fix CVE-2024-8695, update Docker Desktop to version 4.34.2 or later.
3
What are the potential impacts of CVE-2024-8695?
CVE-2024-8695 can allow an attacker to execute arbitrary code on the host system via a malicious Docker extension.
4
Who is affected by CVE-2024-8695?
Users of Docker Desktop versions prior to 4.34.2 are affected by CVE-2024-8695.
5
Can CVE-2024-8695 be exploited remotely?
Yes, CVE-2024-8695 can be exploited remotely through malicious Docker extensions.