CVE-2010-2793
spice activex/spicec named pipe races
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.
Condición de carrera en el plug-in SPICE (también conocido como spice-activex) para Internet Explorer en Red Hat Enterprise Virtualization (RHEV) Manager, en versiones anteriores a la 2.2.4, permite a usuarios locales crear una cierta tubería (pipe), y obtener privilegios, mediante vectores involucrados en el conocimiento del nombre de esta tubería junto con el uso de la función ImpersonateNamedPipeClient.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-07-22 CVE Reserved
- 2010-12-08 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://securitytracker.com/id?1024825 | Vdb Entry | |
http://www.securityfocus.com/bid/45213 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=620355 | 2010-12-06 | |
https://rhn.redhat.com/errata/RHSA-2010-0818.html | 2013-01-16 | |
https://access.redhat.com/security/cve/CVE-2010-2793 | 2010-12-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Spice-activex Search vendor "Redhat" for product "Spice-activex" | - | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Virtualization Manager Search vendor "Redhat" for product "Enterprise Virtualization Manager" | <= 2.2.3 Search vendor "Redhat" for product "Enterprise Virtualization Manager" and version " <= 2.2.3" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Virtualization Manager Search vendor "Redhat" for product "Enterprise Virtualization Manager" | 2.1 Search vendor "Redhat" for product "Enterprise Virtualization Manager" and version "2.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Virtualization Manager Search vendor "Redhat" for product "Enterprise Virtualization Manager" | 2.2 Search vendor "Redhat" for product "Enterprise Virtualization Manager" and version "2.2" | - |
Affected
|