Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-15514


HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\pipe\dockerBackend named pipe without verifying the validity of the deserialized .NET objects. This would allow a malicious user in the "docker-users" group (who may not otherwise have administrator access) to escalate to administrator privileges.


Published

2018-09-01T01:29:00.233

Last Modified

2024-11-21T03:50:59.077

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-502

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application docker docker 1.10.0.0-0 Yes
Application docker docker 1.10.1.42-1 Yes
Application docker docker 1.10.2.12 Yes
Application docker docker 1.10.2.14 Yes
Application docker docker 1.10.4.0 Yes
Application docker docker 1.10.6 Yes
Application docker docker 1.11.0 Yes
Application docker docker 1.11.0 Yes
Application docker docker 1.11.0 Yes
Application docker docker 1.11.0 Yes
Application docker docker 1.11.0 Yes
Application docker docker 1.11.1 Yes
Application docker docker 1.11.1 Yes
Application docker docker 1.11.1 Yes
Application docker docker 1.11.1 Yes
Application docker docker 1.11.1 Yes
Application docker docker 1.11.2 Yes
Application docker docker 1.12.0 Yes
Application docker docker 1.12.0 Yes
Application docker docker 1.12.0 Yes
Application docker docker 1.12.0 Yes
Application docker docker 1.12.0 Yes
Application docker docker 1.12.0 Yes
Application docker docker 1.12.0 Yes
Application docker docker 1.12.0 Yes
Application docker docker 1.12.0 Yes
Application docker docker 1.12.1 Yes
Application docker docker 1.12.1 Yes
Application docker docker 1.12.1 Yes
Application docker docker 1.12.1 Yes
Application docker docker 1.12.1 Yes
Application docker docker 1.12.1 Yes
Application docker docker 1.12.2 Yes
Application docker docker 1.12.2 Yes
Application docker docker 1.12.2 Yes
Application docker docker 1.12.3 Yes
Application docker docker 1.12.3 Yes
Application docker docker 1.12.3 Yes
Application docker docker 1.12.3 Yes
Application docker docker 1.12.5 Yes
Application docker docker 1.13.0 Yes
Application docker docker 1.13.0 Yes
Application docker docker 1.13.0 Yes
Application docker docker 1.13.0 Yes
Application docker docker 1.13.0 Yes
Application docker docker 1.13.0 Yes
Application docker docker 1.13.0 Yes
Application docker docker 1.13.0 Yes
Application docker docker 1.13.0 Yes
Application docker docker 1.13.0 Yes
Application docker docker 1.13.0 Yes
Application docker docker 1.13.1 Yes
Application docker docker 1.13.1 Yes
Application docker docker 1.13.1 Yes
Application docker docker 17.0.4 Yes
Application docker docker 17.0.5 Yes
Application docker docker 17.03.0 Yes
Application docker docker 17.03.0 Yes
Application docker docker 17.03.1 Yes
Application docker docker 17.04.0 Yes
Application docker docker 17.06.0 Yes
Application docker docker 17.06.0 Yes
Application docker docker 17.06.0 Yes
Application docker docker 17.06.0 Yes
Application docker docker 17.06.0 Yes
Application docker docker 17.06.0 Yes
Application docker docker 17.06.1 Yes
Application docker docker 17.06.1 Yes
Application docker docker 17.06.2 Yes
Application docker docker 17.07.0 Yes
Application docker docker 17.07.0 Yes
Application docker docker 17.07.0 Yes
Application docker docker 17.07.0 Yes
Application docker docker 17.07.0 Yes
Application docker docker 17.09.0 Yes
Application docker docker 17.09.0 Yes
Application docker docker 17.09.0 Yes
Application docker docker 17.09.0 Yes
Application docker docker 17.09.0 Yes
Application docker docker 17.09.0 Yes
Application docker docker 17.09.0 Yes
Application docker docker 17.09.1 Yes
Application docker docker 17.10.0 Yes
Application docker docker 17.11.0 Yes
Application docker docker 17.11.0 Yes
Application docker docker 17.11.0 Yes
Application docker docker 17.11.0 Yes
Application docker docker 17.12.0 Yes
Application docker docker 17.12.0 Yes
Application docker docker 17.12.0 Yes
Application docker docker 17.12.0 Yes
Application docker docker 17.12.0 Yes
Application docker docker 17.12.0 Yes
Application docker docker 18.01.0 Yes
Application docker docker 18.02.0 Yes
Application docker docker 18.02.0 Yes
Application docker docker 18.02.0 Yes
Application docker docker 18.03.0 Yes
Application docker docker 18.03.0 Yes
Application docker docker 18.03.0 Yes
Application docker docker 18.03.1 Yes
Application docker docker 18.04.0 Yes
Application docker docker 18.05.0 Yes
Application docker docker 18.05.0 Yes

References