Database/Container, Kubernetes & orchestration
Docker Desktop: Trojan docker-credential-wincred.exe in a world-writable path gives local privilege escalation
CVE-2019-15752Container, Kubernetes & orchestrationKnown exploitedcurated
Impact
Trojan docker-credential-wincred.exe in a world-writable path gives local privilege escalation. [KEV]
Who can reach it
Local user on a developer/build Windows host
What to do
Not a cluster-node issue; patch any Windows build/dev machines that run Docker Desktop
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.