Vulnerabilities > Docker > Desktop > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-07-09 CVE-2024-5652 Unspecified vulnerability in Docker Desktop
In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker daemon config option in Windows containers mode.
local
low complexity
docker
5.5
2023-04-27 CVE-2022-38730 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Docker Desktop
Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling the data-root field inside the DaemonJSON field in the WindowsContainerStartRequest class.
local
high complexity
docker CWE-367
6.3
2020-03-18 CVE-2020-10665 Link Following vulnerability in Docker Desktop
Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnostics with Administrator privileges, leading to arbitrary DACL permissions overwrites and arbitrary file writes.
local
low complexity
docker CWE-59
6.7