PT-2020-12644 · Docker · Docker Desktop

Ceri Coburn

·

Published

2020-05-28

·

Updated

2022-07-12

·

CVE-2020-11492

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Docker Desktop versions through 2.2.0.5
Description An issue allows a local attacker to intercept a connection attempt from Docker Service, which runs as SYSTEM, by setting up their own named pipe with the same name prior to starting Docker. This enables the attacker to impersonate the privileges of the Docker Service.
Recommendations For Docker Desktop versions through 2.2.0.5, update to a version later than 2.2.0.5 to resolve the issue. As a temporary workaround, consider restricting access to named pipes to minimize the risk of exploitation.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11492

Affected Products

Docker Desktop