CISA Known Exploited Vulnerability

CVE-2019-15752

Docker · Desktop Community Edition

Docker Desktop Community Edition Privilege Escalation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-732
Ransomware Unknown

CISA description

Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\.

Required action

Apply updates per vendor instructions.