Docker has released a patch to address a critical vulnerability identified as CVE-2025-9074 in Docker Desktop, which carries a CVSS score of 9.3 out of 10. The flaw allows a malicious container to escape its isolation and hijack the host system, particularly affecting Windows users. On Windows, attackers exploiting this vulnerability can mount the entire C:\ drive, access sensitive files, and escalate privileges to administrator level. While macOS users are less impacted, the vulnerability still poses a security risk. Users are advised to update to Docker Desktop version 4.44.3 to mitigate the threat.
When a SSRF is enough: Full Docker Escape on Windows Docker Desktop (CVE-2025-9074) https://t.co/gGBMa8b6og
Docker Fixes CVE-2025-9074, Critical Container Escape Vulnerability With CVSS Score 9.3 https://t.co/OmbU0hOLNh
Docker Fixes CVE-2025-9074, Critical Container Escape Vulnerability With CVSS Score 9.3: https://t.co/MhSAYcTNGt by The Hacker News #infosec #cybersecurity #technology #news