Advisory Details

June 15th, 2020

Docker Desktop Execution with Unnecessary Privileges Privilege Escalation Vulnerability

ZDI-20-715
ZDI-CAN-10074

CVE ID
CVSS SCORE 7.8, AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AFFECTED VENDORS Docker
AFFECTED PRODUCTS Desktop
VULNERABILITY DETAILS

This vulnerability allows local attackers to escalate privileges on affected installations of Docker Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the Troubleshoot functionality. When performing Troubleshoot, Docker executes user-supplied script with unnecessary privilege. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM.

ADDITIONAL DETAILS

This was fixed in Docker Desktop
Stable: 2.3.0.2
Enterprise: 2.3.0.0-ent
Edge: 2.2.3.0


DISCLOSURE TIMELINE
  • 2020-01-21 - Vulnerability reported to vendor
  • 2020-06-15 - Coordinated public release of advisory
CREDIT 0-duke
BACK TO ADVISORIES