PT-2024-4754 · Docker · Docker Desktop

Äá Minh TuấN

+2

·

Published

2024-04-08

·

Updated

2024-08-07

·

CVE-2024-6222

CVSS v4.0

7.3

High

VectorAV:L/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions: Docker Desktop versions prior to 4.29.0
Description: The issue is related to insufficient restriction of the communication channel for given endpoints, allowing an attacker who has gained access to the Docker Desktop VM through a container breakout to further escape to the host by passing extensions and dashboard related IPC messages. Exploitation requires the "Allow only extensions distributed through the Docker Marketplace" setting to be disabled.
Recommendations: For Docker Desktop versions prior to 4.29.0, update to version 4.29.0 or later to fix the issue on MacOS, Linux, and Windows with Hyper-V backend. Additionally, consider enabling the "Allow only extensions distributed through the Docker Marketplace" setting by default, as introduced in Docker Desktop version 4.31.0, to prevent exploitation. As a temporary workaround, consider disabling the extension-manager until a patch is available. Restrict access to the vulnerable IPC messages to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-05276
CVE-2024-6222
ZDI-24-1019

Affected Products

Docker Desktop