Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog
CVE-2023-0625
8HIGH
What is CVE-2023-0625?
Docker Desktop versions prior to 4.12.0 are susceptible to a remote code execution vulnerability. This can be exploited through a specially crafted extension description or changelog, potentially allowing attackers to execute arbitrary code on the host machine. Users are advised to upgrade to version 4.12.0 or later to mitigate this risk.
Affected Version(s)
Docker Desktop Windows 0 < 4.12.0