Skip to content
COOEY

EXPOSURES › CVE-2019-15752

CVE-2019-15752

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-15752 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

A privilege escalation flaw in Docker Desktop Community Edition allowed local users to escalate privileges by placing a trojan horse file in a specific directory.

Local users could escalate privileges by placing a malicious file in a Docker Desktop directory, enabling arbitrary code execution on the host. DIB orgs must ensure Docker Desktop is patched and restricted, as this flaw was actively exploited in the wild and represents a significant supply-chain and unpatched risk.

Shame score — The vulnerability was actively exploited in the wild and allowed privilege escalation, indicating a severe, avoidable failure in Docker's security posture.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -1.00
cooey ↗ severe-fallout -1.00
"…"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.