Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-15664

27
FAUCET Score

CVE-2018-15664 is a critical symlink-exchange vulnerability with directory traversal in Docker through version 18.06.1-ce-rc2, specifically impacting the 'docker cp' command. This flaw allows an attacker to gain arbitrary read-write access to the host filesystem with root privileges due to improper archive operations. With a CVSS score of 7.5 (High), exploitation requires local access, high attack complexity, and user interaction, but can lead to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness of its potential impact.

Impacted Technologies

VendorProductVersion(s)CPE
17.06.0-ceCPE matchmatch criteria
cpe:2.3:a:docker:docker:17.06.0-ce:*:*:*:community:*:*:*
17.06.0-ceCPE matchmatch criteria
cpe:2.3:a:docker:docker:17.06.0-ce:rc1:*:*:community:*:*:*
17.06.0-ceCPE matchmatch criteria
cpe:2.3:a:docker:docker:17.06.0-ce:rc2:*:*:community:*:*:*
17.06.0-ceCPE matchmatch criteria
cpe:2.3:a:docker:docker:17.06.0-ce:rc3:*:*:community:*:*:*
17.06.0-ceCPE matchmatch criteria
cpe:2.3:a:docker:docker:17.06.0-ce:rc4:*:*:community:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
0.8
Impact Score
6.0
CvssVersion
3.0

Exploit Intelligence

EPSS Score
3.40%
Probability of exploitation in next 30 days
EPSS Percentile
87.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0340 is in the 100th percentile among its peer group of 39 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.2 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.5 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

microsoftpatch availablevia msrc
Product: Microsoft Azure Kubernetes Service
microsoftpatch availablevia msrc
Product: Azure IoT Edge
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 ExtrasFixed in: docker-2:1.13.1-102.git7f2769b.el7
View patch
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 3.6Fixed in: docker
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 3.7Fixed in: docker

Vendor Advisories (2)

microsoft2019-Jul/CVE-2018-15664Important

Docker Elevation of Privilege Vulnerability

Jul 9, 2019
redhatCVE-2018-15664Moderate

docker: symlink-exchange race attacks in docker cp

May 23, 2019

References

lists.opensuse.org / opensuse-security-announce/2019-06/msg00066.html
lists.opensuse.org / opensuse-security-announce/2019-09/msg00001.html
access.redhat.com / errata/RHSA-2019:1910
bugzilla.suse.com / show_bug.cgi
ExploitIssue TrackingThird Party Advisory
github.com / moby/moby/pull/39252
Issue TrackingThird Party Advisory
portal.msrc.microsoft.com / en-US/security-guidance/advisory/CVE-2018-15664
usn.ubuntu.com / 4048-1
openwall.com / lists/oss-security/2019/05/28/1
ExploitMailing ListThird Party Advisory
openwall.com / lists/oss-security/2019/08/21/1
securityfocus.com / bid/108507
Third Party AdvisoryVDB Entry
access.redhat.com / security/cve/cve-2018-15664
Third Party Advisory