Privilege Escalation in Docker Desktop by Docker
CVE-2020-15360

7.8HIGH

Key Information:

Vendor

Docker

Vendor
CVE Published:
27 June 2020

What is CVE-2020-15360?

The vulnerability in Docker Desktop arises from the com.docker.vmnetd component, which lacks appropriate client verification. This oversight opens the door for attackers to escalate their privileges, potentially allowing unauthorized access and control over system-level resources. This flaw can significantly compromise the security of users running affected versions of Docker Desktop.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.