NA

CVE-2022-38730

Published: 27/04/2023 Updated: 09/05/2023
CVSS v3 Base Score: 6.3 | Impact Score: 5.2 | Exploitability Score: 1
VMScore: 0

Vulnerability Summary

Docker Desktop for Windows prior to 4.6 allows malicious users to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling the data-root field inside the DaemonJSON field in the WindowsContainerStartRequest class. This allows exploiting a symlink vulnerability in ..\dataRoot\network\files\local-kv.db because of a TOCTOU race condition.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

docker desktop