Advisory Details

February 5th, 2026

Docker Desktop for Windows Incorrect Permission Assignment Privilege Escalation Vulnerability

ZDI-26-068
ZDI-CAN-28542

CVE ID CVE-2025-14740
CVSS SCORE 6.7, AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
AFFECTED VENDORS Docker
AFFECTED PRODUCTS Desktop
VULNERABILITY DETAILS

This vulnerability allows local attackers to escalate privileges on affected installations of Docker Desktop for Windows. User interaction on the part of an administrator is required to exploit this vulnerability.

The specific flaw exists within the product installer. The issue results from incorrect permissions on a folder. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a target user.

ADDITIONAL DETAILS

Fixed in version 4.57.0
https://docs.docker.com/desktop/release-notes/


DISCLOSURE TIMELINE
  • 2025-11-14 - Vulnerability reported to vendor
  • 2026-02-05 - Coordinated public release of advisory
  • 2026-02-05 - Advisory Updated
CREDIT Nitesh Surana (niteshsurana.com) and Amol Dosanjh of Trend Research
BACK TO ADVISORIES