Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run 'docker login' to force the command.
References
Configurations
History
22 Oct 2025, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Information
Published : 2019-08-28 21:15
Updated : 2025-10-22 00:16
NVD link : CVE-2019-15752
Mitre link : CVE-2019-15752
CVE.ORG link : CVE-2019-15752
JSON object : View
Products Affected
docker
- docker
microsoft
- windows
apache
- geode
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
