CVE-2025-9164
Severity CVSS v4.0:
HIGH
Type:
CWE-427
Uncontrolled Search Path Element
Publication date:
27/10/2025
Last modified:
30/10/2025
Description
Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder before checking system directories, allowing local privilege escalation through malicious DLL placement.This issue affects Docker Desktop: through 4.48.0.



