CVE-2025-3224 - CVE House
Back to Database
Status published High CVE-2025-3224

Elevation of Privilege in Docker Desktop for Windows during Upgrade due to Insecure Directory Deletion

Vulnerability Description

A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate privileges to SYSTEM. During an update, Docker Desktop attempts to delete files and subdirectories under the path C:\ProgramData\Docker\config with high privileges. However, this directory often does not exist by default, and C:\ProgramData\ allows normal users to create new directories. By creating a malicious Docker\config folder structure at this location, an attacker can force the privileged update process to delete or manipulate arbitrary system files, leading to Elevation of Privilege.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-3224

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Dong-uk Kim, KAIST Hacking Lab

Affected Vendor

Affected Software

Docker Desktop
Vulnerable Versions:
0

Timeline

Official Publish: April 28th, 2025
Last Modified: April 28th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)