MEDIUM · 6.8

CVE-2010-2793

Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and co...

Vulnerability Description

Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
RedhatSpice-Activex-
RedhatEnterprise Virtualization Manager<= 2.2.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-2793?

CVE-2010-2793 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and co...

How severe is CVE-2010-2793?

CVE-2010-2793 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-2793?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Spice-Activex, Redhat Enterprise Virtualization Manager.