CVE-2025-9164
Published: 27 October 2025
Summary
CVE-2025-9164 is a high-severity Uncontrolled Search Path Element (CWE-427) vulnerability in Docker Desktop Installer (inferred from references). Its CVSS base score is 8.8 (High).
Operationally, ranked at the 3.0th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-36191
Vulnerability details
Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder before checking system directories, allowing local privilege escalation through malicious DLL placement.This issue affects Docker…
more
Desktop: through 4.48.0.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.