ZDI-CAN-27571: ZDI-26-260: (0Day) Docker Desktop System Editor Uncontrolled Search Path Element Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Docker Desktop. An attacker must first obtain the ability to escape the container and execute high-privileged code within the Docker Hyper-V VM in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27571?
The severity of ZDI-CAN-27571 is high, as it allows local attackers to escalate privileges on affected installations of Docker Desktop.
How do I fix ZDI-CAN-27571?
To fix ZDI-CAN-27571, ensure you update Docker Desktop to the latest version that addresses this vulnerability.
What does ZDI-CAN-27571 impact?
ZDI-CAN-27571 specifically impacts Docker Desktop installations, allowing privilege escalation for local attackers.
Can ZDI-CAN-27571 be exploited remotely?
No, ZDI-CAN-27571 requires local access to exploit since an attacker must escape the container first.
What is the nature of the vulnerability in ZDI-CAN-27571?
ZDI-CAN-27571 is an uncontrolled search path element issue that leads to privilege escalation.