ZDI-CAN-23779: ZDI-24-1019: (Pwn2Own) Docker Desktop extension-manager Exposed Dangerous Function Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Docker Desktop. An attacker must first obtain the ability to execute high-privileged code within the container in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2024-6222.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23779?
The ZDI-CAN-23779 vulnerability has been assigned a CVSS rating of 8, indicating a high severity level.
How do I fix ZDI-CAN-23779?
To fix ZDI-CAN-23779, update your Docker Desktop installation to the latest version that addresses this privilege escalation issue.
Who is affected by ZDI-CAN-23779?
Users of Docker Desktop who allow local execution of high-privileged code in containers may be affected by ZDI-CAN-23779.
Can ZDI-CAN-23779 be exploited remotely?
No, ZDI-CAN-23779 requires local access to exploit, as the attacker must execute high-privileged code within the container.
What type of vulnerability is ZDI-CAN-23779?
ZDI-CAN-23779 is classified as a privilege escalation vulnerability affecting Docker Desktop.