CVE-2025-15558
Docker Docker CLI, Compose, Assisted Installer for Red Hat OpenShift Container Platform 2
Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this directory and place malicious CLI plugin binaries (docker-compose.exe, docker-buildx.exe, etc.) that are executed when a victim user opens Docker Desktop or invokes Docker CLI plugin features, and allow privilege-escalation if the docker CLI is executed as a privileged user. This issue affects Docker CLI: through 29.1.5 and Windows binaries acting as a CLI-plugin manager using the github.com/docker/cli/cli-plugins/man...
- CVSS
- 7
- EPSS
- 0.47% 38.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.03.05