¡¾Îó²îͨ¸æ¡¿Docker Desktop ÈÝÆ÷ԽȨ»á¼ûÎó²î(CVE?2025?9074)
Ðû²¼Ê±¼ä 2025-08-22Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Docker DesktopÈÝÆ÷ԽȨ»á¼ûÎó²î | ||
CVE ID | CVE-2025-9074 | ||
Îó²îÀàÐÍ | ԽȨ»á¼û | ·¢Ã÷ʱ¼ä | 2025-08-22 |
Îó²îÆÀ·Ö | 9.3 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍâµØ | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Docker DesktopÊÇDocker¹Ù·½ÌṩµÄÒ»¿î×ÀÃæ¶ËÓ¦Ó㬣¬£¬Ö÷ÒªÓÃÓÚÔÚWindowsºÍmacOSϵͳÉϱã½ÝµØÔËÐкÍÖÎÀíLinuxÈÝÆ÷¡£¡£¡£¡£¡£Ëü¼¯³ÉÁËDocker Engine¡¢Docker CLI¡¢Docker ComposeµÈ½¹µã×é¼þ£¬£¬£¬²¢Ö§³ÖWSL 2ºó¶Ë¡¢Kubernetes¼¯ÈºµÈ¹¦Ð§£¬£¬£¬ÊʺϿª·¢ÕßÔÚÍâµØ¹¹½¨¡¢²âÊԺ͵÷ÊÔÈÝÆ÷»¯Ó¦Óᣡ£¡£¡£¡£Óû§¿Éͨ¹ýͼÐνçÃæ»òÏÂÁîÐиßЧÖÎÀíÈÝÆ÷¡¢¾µÏñºÍÍøÂç×ÊÔ´£¬£¬£¬ÊÇ¿ª·¢ÇéÐÎÖг£ÓõÄÈÝÆ÷ÖÎÀí¹¤¾ß¡£¡£¡£¡£¡£
2025Äê8ÔÂ22ÈÕ£¬£¬£¬°ÙÀÖ²©¼¯ÍÅVSRC¼à²âµ½Docker Desktop±£´æÈÝÆ÷ԽȨ»á¼ûÎó²î,¸ÃÎó²îÔÊÐíÍâµØÔËÐеĶñÒâLinuxÈÝÆ÷ÈÆ¹ý¸ôÀë»úÖÆ£¬£¬£¬Í¨¹ýĬÈÏ×ÓÍø£¨192.168.65.7:2375£©Ö±½Ó»á¼ûDocker Engine API¡£¡£¡£¡£¡£¸ÃÎó²î²»ÒÀÀµ¹ÒÔØDocker socket£¬£¬£¬Ò²²»ÊÜ¡°Expose daemon on tcp://localhost:2375 without TLS¡±¿ª¹Ø»òEnhanced Container Isolation£¨ECI£©ÉèÖÃÓ°Ïì¡£¡£¡£¡£¡£Ò»µ©±»Ê¹Ó㬣¬£¬¹¥»÷Õß¿ÉÖ´Ðн¨ÉèºÍ¿ØÖÆÈÝÆ÷¡¢ÖÎÀí¾µÏñµÈ¸ßȨÏÞ²Ù×÷£¬£¬£¬ÉõÖÁÔÚWindows+WSLÇéÐÎϹÒÔØËÞÖ÷»ú´ÅÅ̲¢»á¼ûÓû§¼¶È¨ÏÞÎļþ¡£¡£¡£¡£¡£Îó²îÆÀ·Ö9.3£¬£¬£¬Îó²î¼¶±ðÑÏÖØ¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Docker Desktop < 4.44.3¡£¡£¡£¡£¡£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ