SB2018090103 - Deserialization of Untrusted Data in Docker



SB2018090103 - Deserialization of Untrusted Data in Docker

Published: September 1, 2018 Updated: August 8, 2020

Security Bulletin ID SB2018090103
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Deserialization of Untrusted Data (CVE-ID: CVE-2018-15514)

The vulnerability allows a remote authenticated user to execute arbitrary code.

HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \.pipedockerBackend named pipe without verifying the validity of the deserialized .NET objects. This would allow a malicious user in the "docker-users" group (who may not otherwise have administrator access) to escalate to administrator privileges.


Remediation

Install update from vendor's website.