Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-2793

Опубликовано: 08 дек. 2010
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:spice-activex:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_virtualization_manager:*:*:*:*:*:*:*:*
Версия до 2.2.3 (включая)
cpe:2.3:o:redhat:enterprise_virtualization_manager:2.1:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_virtualization_manager:2.2:*:*:*:*:*:*:*

EPSS

Процентиль: 45%
0.00229
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-362

Связанные уязвимости

redhat
около 15 лет назад

Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.

github
больше 3 лет назад

Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.

EPSS

Процентиль: 45%
0.00229
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-362