Docker Desktop for Windows before... CVE-2022-37326

- AV AC AU C I A
发布: 2023-04-27
修订: 2025-01-31

Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by controlling the pidfile field inside the DaemonJSON field in the WindowsContainerStartRequest class. This can indirectly lead to privilege escalation.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息