Docker Exploit Cve 2020 11492
Docker Desktop Privilege Escalation Vulnerability Cve 2020 11492 The vulnerability has been assigned cve 2020 11492 and the latest docker desktop community and enterprise have fixed the issue. when docker desktop for windows is installed, a windows service called docker desktop service is installed. Vulnerability overview: recently, a vulnerability has been discovered in docker desktop. this flaw allows a local user to escalate privilege on the system. vulnerability exist in the docker desktop service. before looking into vulnerability, understand few concepts docker desktop and named pipe.
Docker Desktop Privilege Escalation Vulnerability Cve 2020 11492 An issue was discovered in docker desktop through 2.2.0.5 on windows. if a local attacker sets up their own named pipe prior to starting docker with the same name, this attacker can intercept a connection attempt from docker service (which runs as system), and then impersonate their privileges. An issue was discovered in docker desktop through 2.2.0.5 on windows. if a local attacker sets up their own named pipe prior to starting docker with the same name, this attacker can intercept a connection attempt from docker service (which runs as system), and then impersonate their privileges. The mission of the cve™ program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. An issue was discovered in docker desktop through 2.2.0.5 on windows. if a local attacker sets up their own named pipe prior to starting docker with the same name, this attacker can intercept a connection attempt from docker service (which runs as system), and then impersonate their privileges.
Docker Vulnerabilities And Security Risks Soos The mission of the cve™ program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. An issue was discovered in docker desktop through 2.2.0.5 on windows. if a local attacker sets up their own named pipe prior to starting docker with the same name, this attacker can intercept a connection attempt from docker service (which runs as system), and then impersonate their privileges. An issue was discovered in docker desktop through 2.2.0.5 on windows. if a local attacker sets up their own named pipe prior to starting docker with the same name, this attacker can intercept a connection attempt from docker service (which runs as system), and then impersonate their privileges. An issue was discovered in docker desktop through 2.2.0.5 on windows. if a local attacker sets up their own named pipe prior to starting docker with the same name, this attacker can intercept a connection attempt from docker service (which runs as system), and then impersonate their privileges. An issue was discovered in docker desktop through 2.2.0.5 on windows. if a local attacker sets up their own named pipe prior to starting docker with the same name, this attacker can intercept a connection attempt from docker service (which runs as system), and then impersonate their privileges. Cve 2020 11492 was a critical privilege escalation vulnerability in docker desktop for windows that allowed attackers to gain system privileges through windows named pipe impersonation.
Comments are closed.