CVE-2022-37326

HIGH

Docker Desktop < 4.6.0 - Unauthenticated Arbitrary File Deletion via WindowsContainerStartRequest DaemonJSON pidfile

Title source: llm
STIX 2.1

Description

Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by controlling the pidfile field inside the DaemonJSON field in the WindowsContainerStartRequest class. This can indirectly lead to privilege escalation.

Scores

CVSS v3 7.8
EPSS 0.0029
EPSS Percentile 21.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (1)
docker/desktop < 4.6.0
Published Apr 27, 2023
Tracked Since Feb 18, 2026