DLL Hijacking Vulnerability in Docker Desktop by Docker
CVE-2025-9164
8.8HIGH
What is CVE-2025-9164?
The Docker Desktop Installer.exe has a vulnerability that allows DLL hijacking through an insecure search order for required DLLs. The installer prioritizes looking for DLLs in the user's Downloads folder before navigating to system directories. This flaw enables potential attackers to execute local privilege escalation by placing malicious DLL files in the Downloads folder, thereby compromising the integrity of the Docker Desktop installation. Users are advised to take precautions to secure their installations against this vulnerability.
Affected Version(s)
Docker Desktop Windows 0 <= 4.48.0
