CVE-2025-9164

Severity CVSS v4.0:
HIGH
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
27/10/2025
Last modified:
30/10/2025

Description

Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder before checking system directories, allowing local privilege escalation through malicious DLL placement.This issue affects Docker Desktop: through 4.48.0.

References to Advisories, Solutions, and Tools