CVE-2025-15558

Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this directory and place malicious CLI plugin binaries (docker-compose.exe, docker-buildx.exe, etc.) that are executed when a victim user opens Docker Desktop or invokes Docker CLI plugin features, and allow privilege-escalation if the docker CLI is executed as a privileged user. This issue affects Docker CLI: through 29.1.5 and Windows binaries acting as a CLI-plugin manager using the github.com/docker/cli/cli-plugins/manager https://pkg.go.dev/github.com/docker/cli@v29.1.5+incompatible/cli-plugins/manager  package, such as Docker Compose. This issue does not impact non-Windows binaries, and projects not using the plugin-manager code.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:docker:command_line_interface:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

30 Jun 2026, 03:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/security/cve/CVE-2025-15558 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2444574 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15558.json -

17 Jun 2026, 08:38

Type Values Removed Values Added
Summary
  • (es) Docker CLI para Windows busca binarios de plugin en C:\ProgramData\Docker\cli-plugins, un directorio que no existe por defecto. Un atacante de bajo privilegio puede crear este directorio y colocar binarios de plugin CLI maliciosos (docker-compose.exe, docker-buildx.exe, etc.) que se ejecutan cuando un usuario víctima abre Docker Desktop o invoca funciones de plugin de Docker CLI, y permiten la escalada de privilegios si el Docker CLI se ejecuta como un usuario privilegiado. Este problema afecta a Docker CLI: hasta la versión 29.1.5 y a los binarios de Windows que actúan como un gestor de plugin CLI utilizando el paquete github.com/docker/cli/cli-plugins/manager https://pkg.go.dev/github.com/docker/cli@v29.1.5+incompatible/cli-plugins/manager, como Docker Compose. Este problema no tiene impacto en los binarios que no son de Windows, ni en los proyectos que no utilizan el código del gestor de plugins.

09 Mar 2026, 17:38

Type Values Removed Values Added
First Time Docker command Line Interface
Docker
Microsoft
Microsoft windows
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:docker:command_line_interface:*:*:*:*:*:*:*:*
References () https://docs.docker.com/desktop/release-notes/ - () https://docs.docker.com/desktop/release-notes/ - Release Notes
References () https://github.com/docker/cli/pull/6713 - () https://github.com/docker/cli/pull/6713 - Issue Tracking, Patch
References () https://www.zerodayinitiative.com/advisories/ZDI-CAN-28304/ - () https://www.zerodayinitiative.com/advisories/ZDI-CAN-28304/ - Not Applicable
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0

04 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-04 17:16

Updated : 2026-07-15 02:17


NVD link : CVE-2025-15558

Mitre link : CVE-2025-15558

CVE.ORG link : CVE-2025-15558


JSON object : View

Products Affected

docker

  • command_line_interface

microsoft

  • windows
CWE
CWE-427

Uncontrolled Search Path Element