CVE-2010-4423
OracleRemExecService Command Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in the Cluster Verify Utility component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1, when running on Windows, allows local users to affect confidentiality, integrity, and availability via unknown vectors.
Vulnerabilidad sin especificar en el componente "Cluster Verify Utility" (utilidad de verificación de cluster) de Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, y 11.2.0.1. Si se ejecuta en Windows, permite a usuarios locales afectar la confidencialidad, integridad y disponibilidad a través de vectores desconocidos.
It is possible to execute arbitrary operating system commands as localsystem when certain maintenance tasks are executed. For instance, when Database Configuration Assistant is invoked or Oracle Universal Installer is used to modify features. These tools use a Windows service to execute various commands: the service itself relies on a named pipe to receive the commands. The pipe handling is not secure enough resulting in the vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-12-06 CVE Reserved
- 2011-01-19 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/42895 | Third Party Advisory | |
http://www.securityfocus.com/bid/45859 | Vdb Entry | |
http://www.securitytracker.com/id?1024972 | Vdb Entry | |
http://www.vupen.com/english/advisories/2011/0139 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/64756 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html | 2017-08-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 10.2.0.4 Search vendor "Oracle" for product "Database Server" and version "10.2.0.4" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 10.2.0.5 Search vendor "Oracle" for product "Database Server" and version "10.2.0.5" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 11.1.0.7 Search vendor "Oracle" for product "Database Server" and version "11.1.0.7" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|