ZDI-CAN-27229: ZDI-26-258: (0Day) Docker Desktop extension-manager Exposed Dangerous Function Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Docker Desktop for Windows. An attacker must first obtain the ability to execute high-privileged code within the container in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27229?
The severity of ZDI-CAN-27229 is categorized as a high-risk local privilege escalation vulnerability.
How do I fix ZDI-CAN-27229?
To fix ZDI-CAN-27229, ensure you update Docker Desktop for Windows to the latest version that addresses this vulnerability.
Who is affected by ZDI-CAN-27229?
ZDI-CAN-27229 affects users of Docker Desktop for Windows installations that are not updated with the latest security patches.
What kind of attack exploits ZDI-CAN-27229?
ZDI-CAN-27229 can be exploited by local attackers who gain the ability to execute high-privilege commands.
Is ZDI-CAN-27229 a remote vulnerability?
No, ZDI-CAN-27229 is a local vulnerability that requires the attacker to have local access to the Docker Desktop for Windows system.