EXPOSURES › CVE-2019-15752
CVE-2019-15752
HIGH ⌖ ON CISA KEV · EXPLOITEDA privilege escalation flaw in Docker Desktop Community Edition allowed local users to escalate privileges by placing a trojan horse file in a specific directory.
Local users could escalate privileges by placing a malicious file in a Docker Desktop directory, enabling arbitrary code execution on the host. DIB orgs must ensure Docker Desktop is patched and restricted, as this flaw was actively exploited in the wild and represents a significant supply-chain and unpatched risk.
Shame score — The vulnerability was actively exploited in the wild and allowed privilege escalation, indicating a severe, avoidable failure in Docker's security posture.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\.