CVE-2024-6222
Published: 09 July 2024
Summary
CVE-2024-6222 is a high-severity Improper Restriction of Communication Channel to Intended Endpoints (CWE-923) vulnerability in Docker Desktop. Its CVSS base score is 7.3 (High).
Operationally, ranked in the top 14.8% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-47355
Vulnerability details
In Docker Desktop before v4.29.0, an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passing extensions and dashboard related IPC messages. Docker Desktop v4.29.0 https://docs.docker.com/desktop/release-notes/#4290 fixes the…
more
issue on MacOS, Linux and Windows with Hyper-V backend. As exploitation requires "Allow only extensions distributed through the Docker Marketplace" to be disabled, Docker Desktop v4.31.0 https://docs.docker.com/desktop/release-notes/#4310 additionally changes the default configuration to enable this setting by default.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Authorizing wireless access restricts the wireless communication channel to only intended endpoints.
Approving specific exchanges and documenting interface characteristics restricts communication channels to only intended endpoints and systems.
Limits physical connectivity to transmission channels, supporting restriction of communication paths to only intended endpoints.
Requiring providers to meet communication-channel restrictions and monitoring adherence reduces improper restriction of channels to intended endpoints.
Mandates restriction of the channel for authentication to only the intended trusted endpoints, blocking unauthorized communication paths.
Explicit control of VoIP traffic forces organizations to restrict communication channels to only intended endpoints and protocols.
Explicit internal/external separation restricts name-resolution channels to their intended communication endpoints.
Enforces that the wireless communication channel is usable only by intended endpoints, addressing improper channel restriction.