← Back to CVE List
Vulnerability Intelligence Report
Docker Desktop Community Edition Privilege Escalation Vulnerability

CVE-2019-15752

Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run 'docker login' to force the command.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:29.63%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-732 ↗CWE-732 Incorrect Permission Assignment for Critical Resource

Affected Products & Versions

Vendor Product Affected Versions
docker docker all
microsoft windows all
apache geode 1.12.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
29.628%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2019-08-28T00:00:00
Published2019-08-28T20:24:33
Last Updated2025-10-21T23:45:31

LINK COPIED TO CLIPBOARD