fkie_cve-2020-11492
Vulnerability from fkie_nvd
Published
2020-06-05 14:15
Modified
2024-11-21 04:58
Severity ?
Summary
An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe prior to starting Docker with the same name, this attacker can intercept a connection attempt from Docker Service (which runs as SYSTEM), and then impersonate their privileges.
References
▶ | URL | Tags | |
---|---|---|---|
cve@mitre.org | https://docs.docker.com/docker-for-windows/release-notes/ | Release Notes, Vendor Advisory | |
cve@mitre.org | https://www.pentestpartners.com/security-blog/docker-desktop-for-windows-privesc-cve-2020-11492/ | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://docs.docker.com/docker-for-windows/release-notes/ | Release Notes, Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.pentestpartners.com/security-blog/docker-desktop-for-windows-privesc-cve-2020-11492/ | Third Party Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
docker | docker_desktop | * | |
microsoft | windows | - |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:docker:docker_desktop:*:*:*:*:*:*:*:*", "matchCriteriaId": "AE573D67-DE33-49DE-975C-D36AE5BC6C3D", "versionEndIncluding": "2.2.0.5", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*", "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe prior to starting Docker with the same name, this attacker can intercept a connection attempt from Docker Service (which runs as SYSTEM), and then impersonate their privileges." }, { "lang": "es", "value": "Se detect\u00f3 un problema en Docker Desktop versiones hasta 2.2.0.5 en Windows. Si un atacante local configura su propia tuber\u00eda nombrada antes de iniciar Docker con el mismo nombre, este atacante puede interceptar un intento de conexi\u00f3n desde Docker Service (que se ejecuta como SYSTEM) y luego suplantar sus privilegios" } ], "id": "CVE-2020-11492", "lastModified": "2024-11-21T04:58:00.410", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "HIGH", "cvssData": { "accessComplexity": "LOW", "accessVector": "LOCAL", "authentication": "NONE", "availabilityImpact": "COMPLETE", "baseScore": 7.2, "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C", "version": "2.0" }, "exploitabilityScore": 3.9, "impactScore": 10.0, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "exploitabilityScore": 1.8, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2020-06-05T14:15:10.607", "references": [ { "source": "cve@mitre.org", "tags": [ "Release Notes", "Vendor Advisory" ], "url": "https://docs.docker.com/docker-for-windows/release-notes/" }, { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "https://www.pentestpartners.com/security-blog/docker-desktop-for-windows-privesc-cve-2020-11492/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Release Notes", "Vendor Advisory" ], "url": "https://docs.docker.com/docker-for-windows/release-notes/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://www.pentestpartners.com/security-blog/docker-desktop-for-windows-privesc-cve-2020-11492/" } ], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-362" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…