PT-2023-2594 · Docker · Docker Desktop For Windows

Published

2023-04-27

·

Updated

2025-01-31

·

CVE-2022-34292

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Docker Desktop for Windows versions prior to 4.6.0
Description The issue is related to a symlink attack on the hyperv/create dockerBackendV2 API, allowing attackers to overwrite any file by controlling the DataFolder parameter for DockerDesktop.vhdx. This can lead to unauthorized access, modification, or deletion of data. The vulnerability is associated with errors in handling symbolic links with the DataFolder parameter.
Recommendations For Docker Desktop for Windows versions prior to 4.6.0, update to version 4.6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the DataFolder parameter in the affected API endpoint until a patch is available. Avoid using the DataFolder parameter in the hyperv/create dockerBackendV2 API until the issue is resolved.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02413
CVE-2022-34292

Affected Products

Docker Desktop For Windows