ID:11892 - Exploit for Permissions, Privileges, and Access Controls in Docker Desktop - CVE-2025-9074

 
Main Vulnerability Database Exploits ID:11892 - Exploit for Permissions, Privileges, and Access Controls in Docker Desktop - CVE-2025-9074

ID:11892 - Exploit for Permissions, Privileges, and Access Controls in Docker Desktop - CVE-2025-9074

Published: August 29, 2025


Vulnerability identifier: #VU114330
Vulnerability risk: Medium
CVE-ID: CVE-2025-9074
CWE-ID: CWE-264
Exploitation vector: Remote access
Vulnerable software:
Docker Desktop

Link to public exploit:


Vulnerability description

The vulnerability allows a malicious container to execute arbitrary code on the system.

The vulnerability exists due to improperly imposed security restrictions. A malicious container can access the Docker Engine and launch additional containers without requiring the Docker socket to be mounted, leading to unauthorized access to files on the host system.


Remediation

Install updates from vendor's website.