Docker Desktop for Windows is a container management tool that runs on the Windows system and simplifies application deployment and management through container technology. Docker has released a major security vulnerability update advisory (CVE-2025-9074, CVSS 4.x: 9.3) and a new version. This is a Server-Side Request Forgery (SSRF) vulnerability that allows an attacker to use an
API to execute various privileged commands, including controlling other containers and managing images. In addition, the vulnerability also allows mounting the host drive with the same permissions as the user running Docker Desktop.