SB2025082120 - Security restrictions bypass in Docker Desktop



SB2025082120 - Security restrictions bypass in Docker Desktop

Published: August 21, 2025 Updated: January 9, 2026

Security Bulletin ID SB2025082120
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2025-9074)

The vulnerability allows a malicious container to execute arbitrary code on the system.

The vulnerability exists due to improperly imposed security restrictions. A malicious container can access the Docker Engine and launch additional containers without requiring the Docker socket to be mounted, leading to unauthorized access to files on the host system.


Remediation

Install update from vendor's website.