HIGH · 7.2

CVE-2010-1906

tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timestamp field to validate input to the \\.\pipe\__Repair...

Vulnerability Description

tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timestamp field to validate input to the \\.\pipe\__RepairService_pipe__company named pipe, which allows remote authenticated users to execute arbitrary code by obtaining the current time from (1) tcpip.sys or (2) an SMB2 service.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
ConsonaConsona Dynamic Agent-
ConsonaConsona Repair ManagerAll versions
ConsonaConsona Subscriber ActivationAll versions
ConsonaConsona Subscriber AgentAll versions
MicrosoftWindows 7All versions
MicrosoftWindows VistaAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-1906?

CVE-2010-1906 is a vulnerability with a CVSS score of 7.2 (HIGH). tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timestamp field to validate input to the \\.\pipe\__Repair...

How severe is CVE-2010-1906?

CVE-2010-1906 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-1906?

Check the references section above for vendor advisories and patch information. Affected products include: Consona Consona Dynamic Agent, Consona Consona Repair Manager, Consona Consona Subscriber Activation, Consona Consona Subscriber Agent, Microsoft Windows 7.