CVE-2022-37326

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/04/2023
Last modified:
31/01/2025

Description

Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by controlling the pidfile field inside the DaemonJSON field in the WindowsContainerStartRequest class. This can indirectly lead to privilege escalation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:docker:desktop:*:*:*:*:windows:*:*:* 4.6.0 (excluding)