TROYANOSYVIRUS
Voltar para CVEs

CVE-2019-15752

HIGHCISA KEV
7.8

Descricao

Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run 'docker login' to force the command.

Detalhes CVE

Pontuacao CVSS v3.17.8
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vetor de ataqueLOCAL
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioREQUIRED
Publicado8/28/2019
Ultima modificacao11/6/2025
Fontekev
Avistamentos honeypot0

CISA KEV

FornecedorDocker
ProdutoDesktop Community Edition
Nome da vulnerabilidadeDocker Desktop Community Edition Privilege Escalation Vulnerability
Data inclusao KEV2021-11-03
Prazo de remediacao2022-05-03
Uso em ransomwareUnknown

Produtos afetados

apache:geodedocker:dockermicrosoft:windows

Fraquezas (CWE)

CWE-732CWE-732

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.