CVE-2025-9074

CRITICAL

Docker Desktop - Privilege Escalation

Title source: llm

Description

A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at 192.168.65.7:2375 by default. This vulnerability occurs with or without Enhanced Container Isolation (ECI) enabled, and with or without the "Expose daemon on tcp://localhost:2375 without TLS" option enabled. This can lead to execution of a wide range of privileged commands to the engine API, including controlling other containers, creating new ones, managing images etc. In some circumstances (e.g. Docker Desktop for Windows with WSL backend) it also allows mounting the host drive with the same privileges as the user running Docker Desktop.

Exploits (23)

exploitdb WORKING POC
by aprillefou · textlocalmultiple
https://www.exploit-db.com/exploits/52472
nomisec WORKING POC 46 stars
by BridgerAlderson · poc
https://github.com/BridgerAlderson/CVE-2025-9074-PoC
nomisec WORKING POC 11 stars
by Shaoshi17 · poc
https://github.com/Shaoshi17/CVE-2025-9074-Docker-Exploit
nomisec WORKING POC 11 stars
by zenzue · poc
https://github.com/zenzue/CVE-2025-9074
nomisec WORKING POC 8 stars
by j3r1ch0123 · poc
https://github.com/j3r1ch0123/CVE-2025-9074
github WORKING POC 4 stars
by ctkqiang · gopoc
https://github.com/ctkqiang/CVE-Exploits/tree/main/CVE-2025-9074
nomisec WORKING POC 4 stars
by xwpdx0 · poc
https://github.com/xwpdx0/poc-2025-9074
github SUSPICIOUS 3 stars
by fortihack · pythonpoc
https://github.com/fortihack/CVE-2025-9074
github SCANNER 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-9074
nomisec SUSPICIOUS 1 stars
by fsoc-ghost-0x · poc
https://github.com/fsoc-ghost-0x/CVE-2025-9074_DAEMON_KILLER
nomisec WORKING POC 1 stars
by pppxo · poc
https://github.com/pppxo/CVE-2025-9074-PoC-Bash
nomisec WORKING POC 1 stars
by PtechAmanja · poc
https://github.com/PtechAmanja/CVE-2025-9074-Docker-Desktop-Container-Escape
github WORKING POC 1 stars
by OilSeller2001 · pythonpoc
https://github.com/OilSeller2001/PoC-for-CVE-2025-9074
nomisec WORKING POC 1 stars
by pucagit · poc
https://github.com/pucagit/CVE-2025-9074
nomisec WORKING POC
by chernandez321 · poc
https://github.com/chernandez321/CVE-2025-9074-docker-escape
nomisec WORKING POC
by rocket-panda · poc
https://github.com/rocket-panda/CVE-2025-9074
nomisec SUSPICIOUS
by KvzinNcpx7 · poc
https://github.com/KvzinNcpx7/CVE-2025-9074_DAEMON_KILLER
nomisec WORKING POC
by matesz44 · poc
https://github.com/matesz44/CVE-2025-9074
nomisec SUSPICIOUS
by KvzinNcpx7 · poc
https://github.com/KvzinNcpx7/kvzinncpx7.github.io
nomisec WORKING POC
by x0da6h · poc
https://github.com/x0da6h/POC-for-CVE-2025-9074
nomisec WORKING POC
by zaydbf · poc
https://github.com/zaydbf/CVE-2025-9074-Poc
nomisec WORKING POC
by 3rendil · poc
https://github.com/3rendil/CVE-2025-9074-POC
nomisec WORKING POC
by XRayZen · poc
https://github.com/XRayZen/cve-2025-9074-poc

Scores

CVSS v4 9.3
EPSS 0.0090
EPSS Percentile 75.8%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Details

CWE
CWE-668
Status published
Products (1)
Docker/Docker Desktop 4.25 - 4.44.3
Published Aug 20, 2025
Tracked Since Feb 18, 2026