惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
V
Visual Studio Blog
有赞技术团队
有赞技术团队
T
Tailwind CSS Blog
B
Blog
I
InfoQ
博客园 - 三生石上(FineUI控件)
阮一峰的网络日志
阮一峰的网络日志
F
Fortinet All Blogs
H
Help Net Security
博客园 - Franky
宝玉的分享
宝玉的分享
博客园 - 司徒正美
C
Check Point Blog
G
Google Developers Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Jina AI
Jina AI
T
The Blog of Author Tim Ferriss
MongoDB | Blog
MongoDB | Blog
云风的 BLOG
云风的 BLOG
A
About on SuperTechFans
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
IT之家
IT之家

Exploit-DB.com RSS Feed

MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive OffSec’s Exploit Database Archive
OffSec’s Exploit Database Archive
aprillefou · 2026-02-04 · via Exploit-DB.com RSS Feed
# Exploit Title: Docker Desktop 4.44.3 - Unauthenticated  API Exposure
# Date: 2025-10-06
# Exploit Author: OilSeller2001
# Vendor Homepage: https://www.docker.com/
# Software Link: https://www.docker.com/products/docker-desktop/
# Version: Affected on Windows and macOS versions prior to 4.44.3
# Tested on: Windows 11 + Docker Desktop 4.43.0
# Exploit Type: Remote, Local, Shellcode
# Platform: Windows
# CVE: CVE-2025-9074

# Description:
This PoC script exploits a security misconfiguration in the unauthenticated exposure of the Docker Engine API. 
By sending crafted API requests directly to the Docker daemon, the script creates and starts a specially prepared container. 
The container leverages the bind mount feature to map sensitive directories from the host filesystem into the container, effectively granting arbitrary access to the host. 
This results in a high-privilege remote code execution scenario.

# Vulnerability Details:
The Docker Engine API (TCP port 2375) can be exposed without TLS authentication via the "Expose daemon on tcp://localhost:2375 without TLS" option in Docker Desktop. 
If this option is enabled, any local or remote attacker with network access to the exposed port can control the Docker daemon without authentication.

# Usage:
1. Expose the Docker daemon on TCP 2375 without TLS (testing environment only).
2. Run the PoC against the target:
   python3 poc_cve_2025_9074.py <target_ip>:2375
3. The script will:
   - Check API availability
   - Pull an image
   - Create a malicious container with bind mounts to the host filesystem
   - Start the container, allowing access to host files

# Mitigation:
- Disable the unauthenticated Docker API exposure after testing.
- Use TLS certificates if remote API access is required.
- Restrict network access to port 2375 via firewall rules.

# PoC Download Link:
https://github.com/OilSeller2001/PoC-for-CVE-2025-9074