DLL Hijacking Vulnerability in Docker Desktop by Docker
CVE-2025-9164
What is CVE-2025-9164?
The Docker Desktop Installer.exe has a vulnerability that allows DLL hijacking through an insecure search order for required DLLs. The installer prioritizes looking for DLLs in the user's Downloads folder before navigating to system directories. This flaw enables potential attackers to execute local privilege escalation by placing malicious DLL files in the Downloads folder, thereby compromising the integrity of the Docker Desktop installation. Users are advised to take precautions to secure their installations against this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Docker Desktop Windows 0 <= 4.48.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
