PT-2026-108908 · Docker · Docker Desktop For Windows
CVE-2026-106581
·
Published
2026-10-09
·
Updated
2026-10-09
CVSS v4.0
7.3
High
| Vector | AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Docker Desktop for Windows versions prior to 4.92.0
Description
The Docker Desktop Installer.exe fails to verify the signature of packages provided via the
install -package command. This allows an attacker to execute arbitrary installer actions with LocalSystem privileges if they can provide a crafted package and persuade a user to approve the User Account Control (UAC) prompt.Recommendations
Update Docker Desktop for Windows to version 4.92.0 or later.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docker Desktop For Windows