← Back to browse · API

CVE-2019-15752

Severity
HIGH
CVSS
7.8
EPSS
0.31918
Risk score
67.37
CISA KEV
Yes
PoC
No
Published
2019-08-28
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2019-6687, GHSA-PG68-PRCJ-H956
Products
Docker:Desktop Community Edition, n/a:n/a n/a
Sources
euvd EUVD-2019-6687
cisa.gov CVE-2019-15752

Description

Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run 'docker login' to force the command.

References