ZDI-CAN-27431: ZDI-26-261: (0Day) Docker Desktop credentialHelper Directory Traversal Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Docker Desktop. An attacker must first obtain the ability to escape the container and execute high-privileged code within the Docker Hyper-V VM in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27431?
ZDI-CAN-27431 is considered a high severity vulnerability due to its potential for privilege escalation.
How do I fix ZDI-CAN-27431?
To mitigate ZDI-CAN-27431, update Docker Desktop to the latest version that includes the security patches addressing this vulnerability.
Who is affected by ZDI-CAN-27431?
ZDI-CAN-27431 affects users of Docker Desktop who have not updated their installations to the latest secure version.
What type of vulnerability is ZDI-CAN-27431?
ZDI-CAN-27431 is a directory traversal privilege escalation vulnerability.
Can ZDI-CAN-27431 be exploited remotely?
No, ZDI-CAN-27431 requires local access to the Docker environment to be exploited.