Information
The docker socket docker.sock (Linux) and \.pipedocker_engine (Windows) should not be mounted inside a container, with the exception case being during the installation of Universal Control Plane (UCP) component of Docker Enterprise as it is required for install.
If the docker socket is mounted inside a container it would allow processes running within the container to execute docker commands which effectively allows for full control of the host.
By default, docker.sock (linux) and \.pipedocker_engine (windows) is not mounted inside containers.
Solution
When using the -v/--volume flags to mount volumes to containers in a docker run command, do not use docker.sock as a volume.
A reference for the docker run command can be found at https://docs.docker.com/engine/reference/run/.