Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5p9c-72f9-f98q

Опубликовано: 27 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.8

Описание

Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder before checking system directories, allowing local privilege escalation through malicious DLL placement.This issue affects Docker Desktop: through 4.48.0.

Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder before checking system directories, allowing local privilege escalation through malicious DLL placement.This issue affects Docker Desktop: through 4.48.0.

EPSS

Процентиль: 1%
0.00103
Низкий

8.8 High

CVSS4

Дефекты

CWE-427

Связанные уязвимости

nvd
10 месяцев назад

Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder before checking system directories, allowing local privilege escalation through malicious DLL placement.This issue affects Docker Desktop: through 4.48.0.

CVSS3: 7.8
fstec
10 месяцев назад

Уязвимость установщика платформы для разработки и доставки контейнерных приложений Docker Desktop, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 1%
0.00103
Низкий

8.8 High

CVSS4

Дефекты

CWE-427