ZDI-CAN-23513: ZDI-25-306: Docker Desktop Helper Service Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Docker Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-5652.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23513?
The severity of ZDI-CAN-23513 is rated at 7, indicating a high level of risk.
How do I fix ZDI-CAN-23513?
To fix ZDI-CAN-23513, update Docker Desktop to the latest version that addresses this vulnerability.
Who is affected by ZDI-CAN-23513?
ZDI-CAN-23513 affects installations of Docker Desktop on systems where local attackers can execute low-privileged code.
What type of vulnerability is ZDI-CAN-23513?
ZDI-CAN-23513 is a privilege escalation vulnerability.
What is required to exploit ZDI-CAN-23513?
An attacker must first obtain the ability to execute low-privileged code on the target system to exploit ZDI-CAN-23513.