A severe privilege escalation vulnerability, tracked as CVE-2020-11492, has been addressed in the Windows Docker Desktop Service. The vulnerability affects the way the service uses named pipes when communicating as a client to child processes. The service can be tricked by attackers into connecting to a named pipe that has been set up by a malicious lower privilege process. Then the process can impersonate the Docker Desktop service account and execute arbitrary system commands with the highest level privileges. On May 11, Docker released version 2.3.0.2 that addresses the vulnerability.”]
Source: https://securityaffairs.co/wordpress/103645/hacking/docker-desktop-privilege-escalation.html

