Database/Container, Kubernetes & orchestration
Docker Desktop: Trojan docker-credential-wincred.exe in a world-writable path gives local privilege escalation
CVSS 7.8CVE-2019-15752Container, Kubernetes & orchestrationKnown exploitedcurated
Impact
Trojan docker-credential-wincred.exe in a world-writable path gives local privilege escalation. [KEV]
Who can reach it
Local user on a developer/build Windows host
What to do
Not a cluster-node issue; patch any Windows build/dev machines that run Docker Desktop
References
Related entries
- Kubernetes (kubelet): Windows workloads run as ContainerAdministrator despite runAsNonRootCVE-2021-25749 · Kubernetes (kubelet)High
- containerd: Container root dirs and plugin dirs created world-traversableCVE-2021-41103 · containerdHigh
- CRI-O: Crafted environment variable injects arbitrary lines into /etc/passwdCVE-2022-4318 · CRI-OHigh
- CRI-O: newline in HOME injects arbitrary lines into /etc/passwd, bypassing the CVE-2022-4318 fixCVE-2026-15809 · CRI-O (container HOME environment variable handling)High
- CRIU: a container process can spoof its saved credentials and restore with root UID and capabilitiesCVE-2026-18107 · CRIU checkpoint/restore (rseq parasite injection), as used by Podman and OpenShiftHigh
- Traefik: mTLS bypass via SNI pre-sniffing on fragmented ClientHello packetsCVE-2026-32305 · TraefikHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.