PT-2020-12644 · Docker · Docker Desktop
Ceri Coburn
·
Published
2020-05-28
·
Updated
2022-07-12
·
CVE-2020-11492
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Docker Desktop versions through 2.2.0.5
Description
An issue allows a local attacker to intercept a connection attempt from Docker Service, which runs as SYSTEM, by setting up their own named pipe with the same name prior to starting Docker. This enables the attacker to impersonate the privileges of the Docker Service.
Recommendations
For Docker Desktop versions through 2.2.0.5, update to a version later than 2.2.0.5 to resolve the issue. As a temporary workaround, consider restricting access to named pipes to minimize the risk of exploitation.
Exploit
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docker Desktop