CVE-2019-15752

    Dashboard / Vulnerabilities / CVE-2019-15752

    CVE-2019-15752

    Published: 28 Aug 2019Last Modified: 8 Jul 2026

    Summary:

    Details: Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run 'docker login' to force the command.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 57f17bfa7589b41aea6c05ea8bcddba40285c228
    Fixed -None

    Affected versions

    1.12.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2019-15752 | CVE-DB