Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder before checking system directories, allowing local privilege escalation through malicious DLL placement.This issue affects Docker Desktop: through 4.48.0.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://docs.docker.com/desktop/release-notes/ |
|
History
Mon, 27 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Docker
Docker desktop Microsoft Microsoft windows |
|
| Vendors & Products |
Docker
Docker desktop Microsoft Microsoft windows |
Mon, 27 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Oct 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder before checking system directories, allowing local privilege escalation through malicious DLL placement.This issue affects Docker Desktop: through 4.48.0. | |
| Title | Multiple DLL Search Order Hijacking Vulnerabilities in Docker Desktop Installer for Windows | |
| Weaknesses | CWE-427 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Docker
Published: 2025-10-27T13:53:40.216Z
Updated: 2025-10-28T03:56:02.643Z
Reserved: 2025-08-19T13:19:17.483Z
Link: CVE-2025-9164
Updated: 2025-10-27T14:57:42.528Z
Status : Received
Published: 2025-10-27T14:15:42.797
Modified: 2025-10-27T14:15:42.797
Link: CVE-2025-9164
No data.