4.6
CVSSv2

CVE-2022-25365

Published: 19/02/2022 Updated: 03/06/2022
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Docker Desktop prior to 4.5.1 on Windows allows malicious users to move arbitrary files. NOTE: this issue exists because of an incomplete fix for CVE-2022-23774.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

docker docker

Github Repositories

CVE-2022-25365 The privilege escalation vulnerability in Docker Desktop for Windows reference: wwwcyberarkcom/resources/threat-research-blog/breaking-docker-named-pipes-systematically-docker-desktop-privilege-escalation-part-1 File list pocpy Coded by followboy1999 createsymlinkexe Coded by James Forshaw junction64exe Coded by Mark Russinovich ualapidll come from