CVE-2025-9074 Details
Description
A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at 192.168.65.7:2375 by default. This vulnerability occurs with or without Enhanced Container Isolation (ECI) enabled, and with or without the "Expose daemon on tcp://localhost:2375 without TLS" option enabled. This can lead to execution of a wide range of privileged commands to the engine API, including controlling other containers, creating new ones, managing images etc. In some circumstances (e.g. Docker Desktop for Windows with WSL backend) it also allows mounting the host drive with the same privileges as the user running Docker Desktop.
A vulnerability in Docker Desktop allows local Linux containers to access the Docker Engine API over the default Docker subnet. This issue exists with or without Enhanced Container Isolation (ECI) enabled, and regardless of the 'Expose daemon on tcp://localhost:2375 without TLS' option. The vulnerability enables execution of privileged commands via the Engine API, such as managing containers and images. In some cases, it also allows mounting host drives with user-level privileges.
Users can update to Docker Desktop version 4.44.3 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 20, 2025CISA-ADP
Assessed Aug 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-668 | Exposure of Resource to Wrong Sphere | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Docker Desktop | < 4.44.3 (semver) |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 25, 2025 | CVE Modified | CVE |
| Aug 25, 2025 | CVE Modified | CVE |
| Aug 25, 2025 | CVE Modified | CISA-ADP |
| Aug 22, 2025 | CVE Modified | CVE |
| Aug 20, 2025 | New CVE Received | [email protected] |
Volerion