ZDI-26-259: (0Day) Docker Desktop cli-plugins Incorrect Permission Assignment Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Docker Desktop for Windows. An attacker must first obtain the ability to escape the container and execute low-privileged code within the Docker Hyper-V VM in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-259?
ZDI-26-259 is considered a critical severity vulnerability due to its potential for local privilege escalation.
How do I fix ZDI-26-259?
To address ZDI-26-259, ensure you update Docker Desktop for Windows to the latest version provided by the vendor.
Who is affected by ZDI-26-259?
ZDI-26-259 affects installations of Docker Desktop for Windows where an attacker can escape a container.
What can attackers do with ZDI-26-259?
Attackers exploiting ZDI-26-259 can escalate their privileges, potentially gaining unauthorized access to the host operating system.
Is there a workaround for ZDI-26-259?
Currently, there are no specific workarounds for ZDI-26-259; the recommended action is to apply the latest updates from Docker.