๐Ÿ” CVE Alert

CVE-2025-9164

UNKNOWN 0.0

Multiple DLL Search Order Hijacking Vulnerabilities in Docker Desktop Installer for Windows

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder before checking system directories, allowing local privilege escalation through malicious DLL placement.This issue affects Docker Desktop: through 4.48.0.

CWE CWE-427
Vendor docker
Product docker desktop
Ecosystems
Industries
Technology
Published Oct 27, 2025
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for docker docker desktop

Be the first to know when new unknown vulnerabilities affecting docker docker desktop are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Docker / Docker Desktop
0 โ‰ค 4.48.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.docker.com: https://docs.docker.com/desktop/release-notes/

Credits

Mahmoud NourEldin