PT-2025-39690 · Docker · Docker Desktop
Published
2025-09-26
·
Updated
2025-09-26
·
CVE-2025-10657
CVSS v4.0
8.7
High
| Vector | AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Docker Desktop version 4.46.0
Description
A software bug in Docker Desktop allowed the configuration for restricting commands to be ignored when passed to Enhanced Container Isolation (ECI). This granted excessive privileges by permitting unrestricted access to powerful Docker commands. The issue specifically affects users of Docker Desktop 4.46.0 with ECI enabled, and containers explicitly allowed to mount the Docker socket. The command restrictions feature, designed to limit commands issued on the Docker socket, was not functioning as intended. ECI is a security feature that enhances container isolation.
Recommendations
Update to a newer version that contains a fix for this vulnerability.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docker Desktop