Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-1906

Опубликовано: 12 мая 2010
Источник: nvd
CVSS2: 7.2
EPSS Низкий

Описание

tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timestamp field to validate input to the \.\pipe__RepairService_pipe__company named pipe, which allows remote authenticated users to execute arbitrary code by obtaining the current time from (1) tcpip.sys or (2) an SMB2 service.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:consona:consona_dynamic_agent:-:-:enterprise:*:*:*:*:*
cpe:2.3:a:consona:consona_dynamic_agent:-:-:marketing:*:*:*:*:*
cpe:2.3:a:consona:consona_dynamic_agent:-:-:support:*:*:*:*:*
cpe:2.3:a:consona:consona_repair_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:consona:consona_subscriber_activation:*:*:*:*:*:*:*:*
cpe:2.3:a:consona:consona_subscriber_agent:*:*:*:*:*:*:*:*

Одно из

cpe:2.3:o:microsoft:windows_7:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.03147
Низкий

7.2 High

CVSS2

Дефекты

CWE-310

Связанные уязвимости

github
больше 3 лет назад

tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timestamp field to validate input to the \\.\pipe\__RepairService_pipe__company named pipe, which allows remote authenticated users to execute arbitrary code by obtaining the current time from (1) tcpip.sys or (2) an SMB2 service.

EPSS

Процентиль: 87%
0.03147
Низкий

7.2 High

CVSS2

Дефекты

CWE-310