PT-2022-16260 · Docker · Docker Desktop

Published

2022-02-01

·

Updated

2022-09-29

·

CVE-2022-23774

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Docker Desktop versions prior to 4.4.4
Description The issue allows attackers to move arbitrary files, potentially leading to a local privilege escalation. Additionally, it may cause a denial-of-service due to link following.
Recommendations For versions prior to 4.4.4, update to version 4.4.4 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-23774
ZDI-22-1046
ZDI-22-1303

Affected Products

Docker Desktop