CVE-2018-15514
HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\pipe\dockerBackend named pipe without verifying the validity of the deserialized .NET objects.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\pipe\dockerBackend named pipe without verifying the validity of the deserialized .NET objects. This would allow a malicious user in the "docker-users" group (who may not otherwise have administrator access) to escalate to administrator privileges.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.47% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- docker/docker
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/105202Third Party Advisory, VDB Entry
- https://docs.docker.com/docker-for-windows/edge-release-notes/Vendor Advisory
- https://docs.docker.com/docker-for-windows/release-notes/Vendor Advisory
- https://srcincite.io/blog/2018/08/31/you-cant-contain-me-analyzing-and-exploiting-an-elevation-of-privilege-in-docker-for-windows.htmlExploit, Third Party Advisory
- http://www.securityfocus.com/bid/105202Third Party Advisory, VDB Entry
- https://docs.docker.com/docker-for-windows/edge-release-notes/Vendor Advisory
- https://docs.docker.com/docker-for-windows/release-notes/Vendor Advisory
- https://srcincite.io/blog/2018/08/31/you-cant-contain-me-analyzing-and-exploiting-an-elevation-of-privilege-in-docker-for-windows.htmlExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.