it's just too easy

it's just too easy

🎙 John Hammond 👥 2.2M 📅 September 3, 2025 ⏱ 16 min 👁 62K 📄 tutorial 🧭 2026-08-17
Available in: English (current) Français

Keywords

Docker DesktopCVE-2025-9074container escapeSSRFWindows

Summary

In this video, John Hammond discusses CVE-2025-9074, a critical vulnerability in Docker Desktop for Windows and macOS that allows a full container escape. The vulnerability, discovered by Felix Boulet, enables any container to access the Docker engine API on an internal IP (192.168.65.7:2375) without authentication. By sending two HTTP POST requests, an attacker can create and start a privileged container that mounts the host’s C drive, gaining full file system access. The video demonstrates the exploit step-by-step, including how to obtain a vulnerable version of Docker Desktop via VirusTotal. The vulnerability is patched in version 4.44.3, and the presenter emphasizes the importance of updating. He also discusses the implications for SSRF attacks and the broader lesson that internal interfaces are not inherently secure. The video includes a proof-of-concept and references to the original research and related resources.

137 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides a high-value demonstration of a real, critical vulnerability, making it highly relevant for cybersecurity professionals and enthusiasts. The argumentation is solid: the presenter clearly explains the vulnerability’s mechanics, the attack vector, and the impact, supported by a live demonstration. He also contextualizes the finding within the broader security landscape, discussing SSRF chaining and the importance of patching. The reasoning is logical and easy to follow, though it relies on the presenter’s authority and the provided sources rather than independent verification.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates strong scientific rigor by referencing the original research blog, the CVE record, and Docker’s release notes. The sources are credible and directly related to the topic. The title, however, is vague and does not reflect the specific content, which could mislead viewers. The presenter also mentions the lack of a bug bounty for the researcher, adding transparency. Overall, the sources are well-integrated and the technical details are accurate, but the title’s lack of specificity is a minor flaw.

179 words

Title / Content Match

The title is catchy but vague; it does not convey the specific topic of the Docker escape vulnerability, though it reflects the presenter's tone.

Quality & Reliability

8/10

The video is a clear, practical demonstration of a real CVE (CVE-2025-9074) with references to the original research and official sources. The explanation is accurate and well-structured, though it relies on the presenter's interpretation and does not include independent verification.

Key Moments

Cited Sources

Concurring Sources

External References

Contribution & Novelties

This video provides a clear, hands-on demonstration of a critical Docker Desktop vulnerability, making it accessible to a broad audience. It highlights the importance of internal network isolation and the risks of SSRF. The presenter’s step-by-step approach and practical tips for obtaining vulnerable versions add educational value.

Pour aller plus loin :

83 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level, indicating that the video is informative and trustworthy but may not be extremely deep for experts. The overall balance suggests a well-rounded educational resource.

Reliability 8/10

💬 The comments are predominantly positive, with viewers expressing appreciation for the clear explanation and the significance of the finding. Some users share their own experiences and questions, indicating engagement and interest. Overall, the sentiment is positive and constructive.