Vulnerability Details CVE-2025-15558
Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this directory and place malicious CLI plugin binaries (docker-compose.exe, docker-buildx.exe, etc.) that are executed when a victim user opens Docker Desktop or invokes Docker CLI plugin features, and allow privilege-escalation if the docker CLI is executed as a privileged user.
This issue affects Docker CLI: through 29.1.5 and Windows binaries acting as a CLI-plugin manager using the github.com/docker/cli/cli-plugins/manager https://pkg.go.dev/github.com/docker/cli@v29.1.5+incompatible/cli-plugins/manager package, such as Docker Compose.
This issue does not impact non-Windows binaries, and projects not using the plugin-manager code.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.2%
CVSS Severity
CVSS v3 Score 8.0
Products affected by CVE-2025-15558
-
cpe:2.3:a:docker:command_line_interface:18.09.0
-
cpe:2.3:a:docker:command_line_interface:18.09.1
-
cpe:2.3:a:docker:command_line_interface:18.09.2
-
cpe:2.3:a:docker:command_line_interface:18.09.3
-
cpe:2.3:a:docker:command_line_interface:18.09.4
-
cpe:2.3:a:docker:command_line_interface:18.09.5
-
cpe:2.3:a:docker:command_line_interface:18.09.6
-
cpe:2.3:a:docker:command_line_interface:18.09.7
-
cpe:2.3:a:docker:command_line_interface:18.09.8
-
cpe:2.3:a:docker:command_line_interface:18.09.9
-
cpe:2.3:a:docker:command_line_interface:19.03.0
-
cpe:2.3:a:docker:command_line_interface:19.03.1
-
cpe:2.3:a:docker:command_line_interface:19.03.10
-
cpe:2.3:a:docker:command_line_interface:19.03.11
-
cpe:2.3:a:docker:command_line_interface:19.03.12
-
cpe:2.3:a:docker:command_line_interface:19.03.13
-
cpe:2.3:a:docker:command_line_interface:19.03.14
-
cpe:2.3:a:docker:command_line_interface:19.03.15
-
cpe:2.3:a:docker:command_line_interface:19.03.2
-
cpe:2.3:a:docker:command_line_interface:19.03.3
-
cpe:2.3:a:docker:command_line_interface:19.03.4
-
cpe:2.3:a:docker:command_line_interface:19.03.5
-
cpe:2.3:a:docker:command_line_interface:19.03.6
-
cpe:2.3:a:docker:command_line_interface:19.03.7
-
cpe:2.3:a:docker:command_line_interface:19.03.8
-
cpe:2.3:a:docker:command_line_interface:19.03.9
-
cpe:2.3:a:docker:command_line_interface:20.10.0
-
cpe:2.3:a:docker:command_line_interface:20.10.1
-
cpe:2.3:a:docker:command_line_interface:20.10.2
-
cpe:2.3:a:docker:command_line_interface:20.10.3
-
cpe:2.3:a:docker:command_line_interface:20.10.4
-
cpe:2.3:a:docker:command_line_interface:20.10.5
-
cpe:2.3:a:docker:command_line_interface:20.10.6
-
cpe:2.3:a:docker:command_line_interface:20.10.7
-
cpe:2.3:a:docker:command_line_interface:20.10.8
-
cpe:2.3:a:docker:command_line_interface:20.10.9
-
cpe:2.3:o:microsoft:windows:-