
Docker Desktop has been found to have two critical security vulnerabilities that could enable remote code execution (RCE) attacks.
The vulnerabilities, tracked as CVE-2024-8695 with a CVSSv4 score of 9.0, and CVE-2024-8696 with a CVSSv4 score of 8.9, were discovered in Docker Desktop versions prior to 4.34.2. They stem from the way Docker Desktop handles extension descriptions, changelogs, and publisher URLs. By crafting malicious input in these fields, attackers can trick Docker Desktop into executing arbitrary code on the victim’s system.
It is crucial for users to take immediate action to protect themselves. Docker has already released a patched version, 4.34.2, that addresses these vulnerabilities. All users are strongly urged to update this version as soon as possible.