A critical security vulnerability, CVE-2025-9074, has been identified in Docker Desktop, allowing malicious containers to gain unauthorized access to the host system and control the Docker Engine API. Docker has issued updates to patch this flaw, urging users to upgrade immediately to protect their environments. #CVE-2025-9074 #DockerDesktop
Keypoints
- The vulnerability affects Docker Desktop versions running Linux containers locally, regardless of security settings.
- Malicious containers can access the Docker Engine API via a default subnet without mounting the Docker socket.
- This flaw allows attackers to launch additional containers, manipulate Docker images, and access host files with elevated privileges.
- Docker released version 4.44.3 to immediately address and patch the CVE-2025-9074 vulnerability.
- Users are strongly advised to upgrade to the latest Docker Desktop version and monitor for suspicious activity.
Read More: https://thecyberexpress.com/critical-cve-2025-9074-docker-vulnerability/