CVE-2025-36355·Docker vulnerability
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.
- Severity
- high
- Software
- Docker
- Fixed in
- 11.0.1.0
- Published
- 2025-10-06
Affected versions
From: 11.0.0.0
Until: 11.0.1.0
Fixed in: 11.0.1.0
How to fix this CVE
Docker installations running IBM Security Verify Access versions 11.0.0.0 through 11.0.1.0 contain a local privilege escalation vulnerability that allows authenticated users to execute arbitrary scripts outside the intended security boundaries. Update Docker and verify that IBM Security Verify Access is upgraded to version 11.0.1.0 or later to close this attack surface. After patching, restart all affected containers to ensure the fixed version is running.
sudo dnf update docker-ce -yDefensia detects this vulnerability
How to check if you are affected
- Step 1: Run 'docker --version' to confirm the current Docker version installed on the system
- Step 2: Execute 'docker ps -a' and inspect running containers to identify which ones are running IBM Security Verify Access; check container image tags or inspect with 'docker inspect <container_id>' to determine the Verify Access version
- Step 3: Search container logs with 'docker logs <container_id> | grep -i script' or 'docker logs <container_id> | grep -i execute' to look for unexpected script execution or privilege escalation attempts
- Step 4: Verify the patch by running 'docker exec <container_id> /opt/ibm/verify/bin/version.sh' (or equivalent IBM Verify Access version check) to confirm version 11.0.1.0 or later is deployed
FAQ
What is CVE-2025-36355?
CVE-2025-36355 is a local privilege escalation vulnerability in IBM Security Verify Access Docker containers (versions 11.0.0.0–11.0.1.0) that permits authenticated local users to execute arbitrary scripts beyond their intended authorization scope, potentially leading to container breakout or lateral movement.
Is CVE-2025-36355 being actively exploited?
No, CVE-2025-36355 is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog and no public exploit code is available. However, the high CVSS score (8.5) and local attack vector warrant prompt patching in multi-tenant or defense-in-depth environments.
What versions of Docker are affected by CVE-2025-36355?
IBM Security Verify Access versions 11.0.0.0 through 11.0.1.0 running in Docker containers are affected. The vulnerability also affects versions 10.0.0.0 through 10.0.9.0, but all versions should be upgraded to the latest stable release.
How do I check if my server is vulnerable to CVE-2025-36355?
Run 'docker images | grep -i verify' to list IBM Verify Access images, then inspect each with 'docker inspect --format='{{.Config.Labels}}' <image_id>' or check the running container's version using 'docker exec <container_id> cat /opt/ibm/verify/version.txt' (adjust path if needed). Compare the version against 11.0.1.0.
Does Defensia detect CVE-2025-36355?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker or IBM Security Verify Access is installed on a monitored server, CVE-2025-36355 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-36355. Free for 1 server.
Get started free