Docker Desktop Vulnerability Allows Unrestricted Socket Access with Enhanced Container Isolation
CVE-2025-10657

8.7HIGH

Key Information:

Vendor

Docker

Vendor
CVE Published:
26 September 2025

What is CVE-2025-10657?

In Docker Desktop version 4.46.0, a vulnerability exists that undermines Enhanced Container Isolation (ECI) with respect to the command restrictions feature. Administrators intending to restrict commands that can be executed on a Docker socket may find that configuration settings are ignored due to a software bug. This allows any command to be run on the socket without restriction, granting excessive privileges and potentially exposing the system to untrusted operations. It is crucial for users to review their configurations when utilizing ECI with the Docker socket to mitigate potential security risks.

Affected Version(s)

Docker Desktop Windows 4.46.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-10657 : Docker Desktop Vulnerability Allows Unrestricted Socket Access with Enhanced Container Isolation