A critical docker desktop security defect puts Windows hosts at attack risk, so patch now




  • Researchers find 9.3/10 failures in Docker Desktop for Windows and Macos
  • The error allows the threat actors to compromise the underlying hosts and manipulate the data
  • A solution was rapidly launched, so users should patch now

Docker has paveled a vulnerability of critical gravity in its desktop application for Windows and Macos, which could have allowed the threat actors to completely assume vulnerable hosts, exfiltrate confidential data and more.

The vulnerability is described as a falsification of request on the server side (SSRF) and, according to the NVD, “allows Linux local containers to access the Docker engine API through the configured Docker subnet.”

Leave a Comment

Your email address will not be published. Required fields are marked *