Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run 'docker login' to force the command.
2019-08-28T21:15:10.880
2025-03-14T17:32:41.493
Analyzed
CVSSv3.1: 7.8 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | docker | docker | < 2.1.0.1 | Yes |
Operating System | microsoft | windows | - | No |
Application | apache | geode | 1.12.0 | Yes |