CVE-2022-26659
Docker Desktop vulnerability analysis and mitigation

Overview

Docker Desktop installer on Windows in versions before 4.6.0 contained a vulnerability that allowed an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. The vulnerability was discovered on February 10, 2022, and was assigned CVE-2022-26659 on March 7, 2022. The issue affected Docker Desktop installer versions prior to 4.6.0 on Windows systems (GitHub Advisory).

Technical details

The vulnerability existed in the Docker Desktop Installer's log file creation process. When running with elevated privileges, the installer would attempt to create/write install-log.txt in %LOCALAPPDATA%\Docker\ directory with high integrity. An attacker could create a symlink named install-log.txt that points to any arbitrary path, causing the installer to write its log data to the targeted location. If a file already existed at the target location, it would be overwritten with the installer's log data (GitHub Advisory).

Impact

The vulnerability could allow an unprivileged attacker with local system access to overwrite any administrator-writable files on the system, potentially leading to denial of service or other security implications depending on the targeted files (GitHub Advisory).

Mitigation and workarounds

The vulnerability was fixed in Docker Desktop version 4.6.0. The mitigation involved changing the installer to write its log files to a location not writable by non-administrator users, implementing proper Discretionary Access Control List (DACL) for writing the logs (GitHub Advisory, Docker Release Notes).

Additional resources


SourceThis report was generated using AI

Related Docker Desktop vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-9074CRITICAL9.3
  • Docker DesktopDocker Desktop
  • cpe:2.3:a:docker:desktop
NoYesAug 20, 2025
CVE-2025-9164HIGH8.8
  • Docker DesktopDocker Desktop
  • cpe:2.3:a:docker:docker_desktop
NoNoOct 27, 2025
CVE-2025-10657HIGH8.7
  • Docker DesktopDocker Desktop
  • cpe:2.3:a:docker:desktop
NoNoSep 26, 2025
CVE-2025-6587MEDIUM5.2
  • Docker DesktopDocker Desktop
  • cpe:2.3:a:docker:desktop
NoYesJul 03, 2025
CVE-2025-4095MEDIUM4.3
  • Docker DesktopDocker Desktop
  • cpe:2.3:a:docker:desktop
NoYesApr 29, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management