ZDI-26-258: (0Day) Docker Desktop extension-manager Exposed Dangerous Function Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Docker Desktop for Windows. An attacker must first obtain the ability to execute high-privileged code within the container in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-258?
The severity of ZDI-26-258 is critical, as it allows local privilege escalation on Docker Desktop for Windows.
How do I fix ZDI-26-258?
To fix ZDI-26-258, ensure you update Docker Desktop for Windows to the latest version provided by Docker.
Who is affected by ZDI-26-258?
ZDI-26-258 affects users of Docker Desktop for Windows who are running vulnerable versions of the software.
What type of attack does ZDI-26-258 facilitate?
ZDI-26-258 facilitates local privilege escalation attacks by allowing attackers to gain higher privileges on the system.
What should I do if I cannot update to fix ZDI-26-258 immediately?
If you cannot update immediately to fix ZDI-26-258, minimize access to the application and monitor for suspicious activity.