A new vulnerability in Docker Desktop for Windows has revealed how a simple Server-Side Request Forgery (SSRF) attack can lead to a complete compromise of the host system.

The vulnerability, CVE-2025-9074, discovered by Felix Boulet and reported on August 21, 2025, affects all versions of Docker Desktop prior to 4.44.3 and demonstrates how container isolation can be completely bypassed through unauthorized API access. The vulnerability was discovered by chance during a routine network scan and highlights critical gaps in Docker's internal security architecture.
Philippe Dugre from Pivotal Technologies discovered a similar issue on macOS platforms, highlighting the cross-platform nature of this vulnerability.
Docker Desktop for Windows: New vulnerability
The vulnerability is related to the fact that Docker Desktop exposes the internal HTTP API endpoint at https://192.168.65.7:2375/ , without any authentication mechanisms. As a result, any container running in the Docker environment can access this endpoint and perform privileged operations against the host system.
See also: UAC-0057 uses PDF invitation files to execute Shell Scripts
This is a fundamental breakdown of the container isolation model, where workloads should be completely isolated from their hosting environment.
Unfortunately, the risk is high, as minimal technical expertise is required. Attackers only needed basic HTTP request capabilities rather than complex exploit chains or memory corruption techniques.
The exploit process requires only two HTTP POST requests executed from any container environment. The first request targets the /containers/create endpoint with a JSON payload that configures a new privileged container with host filesystem bindings.

The critical configuration parameter involves mounting the Windows C: drive (/mnt/host/c) in a container path (/host_root), providing essentially unrestricted access to the entire host file system.
The JSON payload also specifies execution commands, which are automatically executed upon container startup, allowing immediate post-exploitation activities.
The second HTTP request starts the container execution via the /containers/{id}/start endpoint, activating the malicious container with elevated privileges.
See also: Mozilla Firefox 142: Fix critical vulnerabilities
This two-step process bypasses all of Docker's security checks and gives attackers the same level of access as local administrator accounts.
The vulnerability is particularly insidious because it can be used in the context of SSRF attacks, meaning that attackers are not required to directly execute code inside containers – they only need the ability to trigger HTTP requests from compromised applications or web services running in containerized environments.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Docker Desktop vulnerability: Proof of Concept
There is already a Proof of Concept exploit, which demonstrates the simplicity of exploiting the vulnerability with standard wget commands, which can be executed from any Alpine Linux container.
The exploit creates a privileged container that mounts the host C: drive and executes arbitrary commands.
Docker responded quickly to this revelation, releasing version 4.44.3 with a full fix for the vulnerability. The fix brings proper authentication checks for internal API endpoints and strengthens network separation between container workloads and Docker's control plane.
Security researchers recommend updating to the patched version immediately, as there are no other mitigations for affected systems.
See also: GeoServer: Critical vulnerability allows remote code execution

The disclosure of CVE-2025-9074 in Docker Desktop is not just another vulnerability; it is a wake-up call for the entire containerization community. The case shows how easily the fundamental security model of containers can collapse if internal APIs are not adequately protected. The most worrying aspect is the simplicity of the exploit: two simple HTTP requests are enough to gain full access to the host, which drastically lowers the barriers for an attacker.
In a world where Docker is used by everything from startups to government organizations, such vulnerabilities can become massive attack vectors. SSRF attacks have already proven to be extremely effective, and combined with the cloud-native environment, they multiply the potential targets.
