Lucene search

K
cve[email protected]CVE-2010-2793
HistoryDec 08, 2010 - 6:00 p.m.

CVE-2010-2793

2010-12-0818:00:03
CWE-362
web.nvd.nist.gov
26
cve-2010-2793
race condition
spice
internet explorer
red hat enterprise virtualization
rhev manager
plug-in
security vulnerability

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.

Affected configurations

NVD
Node
redhatspice-activexMatch-
OR
redhatenterprise_virtualization_managerRange2.2.3
OR
redhatenterprise_virtualization_managerMatch2.1
OR
redhatenterprise_virtualization_managerMatch2.2

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2010-2793