Docker Desktop for Windows Incorrect Permission Assignment Vulnerability Allowing Arbitrary Code Execution

Vulnerability

Docker Desktop for Windows has been found to contain multiple vulnerabilities related to incorrect permission assignments in the handling of the C:\ProgramData\DockerDesktop directory. The installer creates this directory without proper ownership verification, leading to two potential exploitation scenarios. In the first scenario, a low-privileged attacker can pre-create the directory before Docker Desktop installation, retaining ownership and later modifying the directory's access control list (ACL) to tamper with critical configuration files, such as install-settings.json, to execute arbitrary code when Docker Desktop is used. The second scenario involves a time-of-check-time-of-use (TOCTOU) race condition during installation, where an attacker can inject malicious files into the directory before the installer applies secure ACLs, achieving the same code execution result.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected system.

Added: Feb 4, 2026, 2:20 PM
Updated: Feb 4, 2026, 5:00 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
2.5
exploitability
3.0
remediation
0.0
relevance
2.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.