peter bassill · operator
$ cve CVE-2019-15752 JSON

CVE-2019-15752 KEV EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 48.6% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run 'docker login' to force the command.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS48.63% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-732
On CISA KEVyes — remediate by 2022-05-03
Public exploityes
Published2019-08-28
Last modified2026-06-17

CISA KEV

NameDocker Desktop Community Edition Privilege Escalation Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productDocker / Desktop Community Edition
Ransomware usenone reported

Affected (3)

VendorProduct
apachegeode
dockerdocker
microsoftwindows

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD