HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\pipe\dockerBackend named pipe without verifying the validity of the deserialized .NET objects. This would allow a malicious user in the "docker-users" group (who may not otherwise have administrator access) to escalate to administrator privileges.
2018-09-01T01:29:00.233
2024-11-21T03:50:59.077
Modified
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | docker | docker | 1.10.0.0-0 | Yes |
| Application | docker | docker | 1.10.1.42-1 | Yes |
| Application | docker | docker | 1.10.2.12 | Yes |
| Application | docker | docker | 1.10.2.14 | Yes |
| Application | docker | docker | 1.10.4.0 | Yes |
| Application | docker | docker | 1.10.6 | Yes |
| Application | docker | docker | 1.11.0 | Yes |
| Application | docker | docker | 1.11.0 | Yes |
| Application | docker | docker | 1.11.0 | Yes |
| Application | docker | docker | 1.11.0 | Yes |
| Application | docker | docker | 1.11.0 | Yes |
| Application | docker | docker | 1.11.1 | Yes |
| Application | docker | docker | 1.11.1 | Yes |
| Application | docker | docker | 1.11.1 | Yes |
| Application | docker | docker | 1.11.1 | Yes |
| Application | docker | docker | 1.11.1 | Yes |
| Application | docker | docker | 1.11.2 | Yes |
| Application | docker | docker | 1.12.0 | Yes |
| Application | docker | docker | 1.12.0 | Yes |
| Application | docker | docker | 1.12.0 | Yes |
| Application | docker | docker | 1.12.0 | Yes |
| Application | docker | docker | 1.12.0 | Yes |
| Application | docker | docker | 1.12.0 | Yes |
| Application | docker | docker | 1.12.0 | Yes |
| Application | docker | docker | 1.12.0 | Yes |
| Application | docker | docker | 1.12.0 | Yes |
| Application | docker | docker | 1.12.1 | Yes |
| Application | docker | docker | 1.12.1 | Yes |
| Application | docker | docker | 1.12.1 | Yes |
| Application | docker | docker | 1.12.1 | Yes |
| Application | docker | docker | 1.12.1 | Yes |
| Application | docker | docker | 1.12.1 | Yes |
| Application | docker | docker | 1.12.2 | Yes |
| Application | docker | docker | 1.12.2 | Yes |
| Application | docker | docker | 1.12.2 | Yes |
| Application | docker | docker | 1.12.3 | Yes |
| Application | docker | docker | 1.12.3 | Yes |
| Application | docker | docker | 1.12.3 | Yes |
| Application | docker | docker | 1.12.3 | Yes |
| Application | docker | docker | 1.12.5 | Yes |
| Application | docker | docker | 1.13.0 | Yes |
| Application | docker | docker | 1.13.0 | Yes |
| Application | docker | docker | 1.13.0 | Yes |
| Application | docker | docker | 1.13.0 | Yes |
| Application | docker | docker | 1.13.0 | Yes |
| Application | docker | docker | 1.13.0 | Yes |
| Application | docker | docker | 1.13.0 | Yes |
| Application | docker | docker | 1.13.0 | Yes |
| Application | docker | docker | 1.13.0 | Yes |
| Application | docker | docker | 1.13.0 | Yes |
| Application | docker | docker | 1.13.0 | Yes |
| Application | docker | docker | 1.13.1 | Yes |
| Application | docker | docker | 1.13.1 | Yes |
| Application | docker | docker | 1.13.1 | Yes |
| Application | docker | docker | 17.0.4 | Yes |
| Application | docker | docker | 17.0.5 | Yes |
| Application | docker | docker | 17.03.0 | Yes |
| Application | docker | docker | 17.03.0 | Yes |
| Application | docker | docker | 17.03.1 | Yes |
| Application | docker | docker | 17.04.0 | Yes |
| Application | docker | docker | 17.06.0 | Yes |
| Application | docker | docker | 17.06.0 | Yes |
| Application | docker | docker | 17.06.0 | Yes |
| Application | docker | docker | 17.06.0 | Yes |
| Application | docker | docker | 17.06.0 | Yes |
| Application | docker | docker | 17.06.0 | Yes |
| Application | docker | docker | 17.06.1 | Yes |
| Application | docker | docker | 17.06.1 | Yes |
| Application | docker | docker | 17.06.2 | Yes |
| Application | docker | docker | 17.07.0 | Yes |
| Application | docker | docker | 17.07.0 | Yes |
| Application | docker | docker | 17.07.0 | Yes |
| Application | docker | docker | 17.07.0 | Yes |
| Application | docker | docker | 17.07.0 | Yes |
| Application | docker | docker | 17.09.0 | Yes |
| Application | docker | docker | 17.09.0 | Yes |
| Application | docker | docker | 17.09.0 | Yes |
| Application | docker | docker | 17.09.0 | Yes |
| Application | docker | docker | 17.09.0 | Yes |
| Application | docker | docker | 17.09.0 | Yes |
| Application | docker | docker | 17.09.0 | Yes |
| Application | docker | docker | 17.09.1 | Yes |
| Application | docker | docker | 17.10.0 | Yes |
| Application | docker | docker | 17.11.0 | Yes |
| Application | docker | docker | 17.11.0 | Yes |
| Application | docker | docker | 17.11.0 | Yes |
| Application | docker | docker | 17.11.0 | Yes |
| Application | docker | docker | 17.12.0 | Yes |
| Application | docker | docker | 17.12.0 | Yes |
| Application | docker | docker | 17.12.0 | Yes |
| Application | docker | docker | 17.12.0 | Yes |
| Application | docker | docker | 17.12.0 | Yes |
| Application | docker | docker | 17.12.0 | Yes |
| Application | docker | docker | 18.01.0 | Yes |
| Application | docker | docker | 18.02.0 | Yes |
| Application | docker | docker | 18.02.0 | Yes |
| Application | docker | docker | 18.02.0 | Yes |
| Application | docker | docker | 18.03.0 | Yes |
| Application | docker | docker | 18.03.0 | Yes |
| Application | docker | docker | 18.03.0 | Yes |
| Application | docker | docker | 18.03.1 | Yes |
| Application | docker | docker | 18.04.0 | Yes |
| Application | docker | docker | 18.05.0 | Yes |
| Application | docker | docker | 18.05.0 | Yes |