Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14218 | A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate privileges to SYSTEM. During an update, Docker Desktop attempts to delete files and subdirectories under the path C:\ProgramData\Docker\config with high privileges. However, this directory often does not exist by default, and C:\ProgramData\ allows normal users to create new directories. By creating a malicious Docker\config folder structure at this location, an attacker can force the privileged update process to delete or manipulate arbitrary system files, leading to Elevation of Privilege. |
Sat, 10 May 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Docker
Docker desktop |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:docker:desktop:*:*:*:*:*:windows:*:* | |
| Vendors & Products |
Docker
Docker desktop |
|
| Metrics |
cvssV3_1
|
Mon, 28 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Apr 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate privileges to SYSTEM. During an update, Docker Desktop attempts to delete files and subdirectories under the path C:\ProgramData\Docker\config with high privileges. However, this directory often does not exist by default, and C:\ProgramData\ allows normal users to create new directories. By creating a malicious Docker\config folder structure at this location, an attacker can force the privileged update process to delete or manipulate arbitrary system files, leading to Elevation of Privilege. | |
| Title | Elevation of Privilege in Docker Desktop for Windows during Upgrade due to Insecure Directory Deletion | |
| Weaknesses | CWE-269 CWE-59 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2025-04-28T19:43:24.060Z
Reserved: 2025-04-03T14:06:28.660Z
Link: CVE-2025-3224
Updated: 2025-04-28T19:43:18.082Z
Status : Analyzed
Published: 2025-04-28T20:15:21.127
Modified: 2025-05-10T00:57:52.993
Link: CVE-2025-3224
No data.
OpenCVE Enrichment
No data.
EUVD