DLL Hijacking Vulnerability in Docker Desktop by Docker
CVE-2025-9164

8.8HIGH

Key Information:

Vendor

Docker

Vendor
CVE Published:
27 October 2025

What is CVE-2025-9164?

The Docker Desktop Installer.exe has a vulnerability that allows DLL hijacking through an insecure search order for required DLLs. The installer prioritizes looking for DLLs in the user's Downloads folder before navigating to system directories. This flaw enables potential attackers to execute local privilege escalation by placing malicious DLL files in the Downloads folder, thereby compromising the integrity of the Docker Desktop installation. Users are advised to take precautions to secure their installations against this vulnerability.

Affected Version(s)

Docker Desktop Windows 0 <= 4.48.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mahmoud NourEldin
.
CVE-2025-9164 : DLL Hijacking Vulnerability in Docker Desktop by Docker