PT-2024-4755 · Docker · Docker Desktop

·

CVE-2024-5652

·

Published

2024-05-05

·

Updated

2025-05-21

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions: Docker Desktop versions prior to 4.31.0
Description: The issue is related to a configuration flaw in the exec-path Docker daemon config option, allowing a user in the docker-users group to cause a Windows Denial-of-Service in Windows containers mode. This is due to inadequate access control. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited. The vulnerability can be exploited through the exec-path Docker daemon config option, which is a part of the Docker Desktop platform for developing and delivering containerized applications.
Recommendations: For Docker Desktop versions prior to 4.31.0, update to version 4.31.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the exec-path Docker daemon config option to minimize the risk of exploitation.

Fix

DoS

Resource Exhaustion

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05277
CVE-2024-5652
ZDI-24-966
ZDI-25-306

Affected Products

Docker Desktop