Docker Desktop Vulnerability Allows Unrestricted Socket Access with Enhanced Container Isolation
CVE-2025-10657
What is CVE-2025-10657?
In Docker Desktop version 4.46.0, a vulnerability exists that undermines Enhanced Container Isolation (ECI) with respect to the command restrictions feature. Administrators intending to restrict commands that can be executed on a Docker socket may find that configuration settings are ignored due to a software bug. This allows any command to be run on the socket without restriction, granting excessive privileges and potentially exposing the system to untrusted operations. It is crucial for users to review their configurations when utilizing ECI with the Docker socket to mitigate potential security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Docker Desktop Windows 4.46.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
