« Volver al listado

CVE-2010-2793

Estado: ModificadaMedia (6.8)—

Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-2793",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-12-08T18:00:03.887",
  "references": [
    {
      "url": "http://securitytracker.com/id?1024825",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/45213",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=620355",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://rhn.redhat.com/errata/RHSA-2010-0818.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://securitytracker.com/id?1024825",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/45213",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=620355",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://rhn.redhat.com/errata/RHSA-2010-0818.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-362"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function."
    },
    {
      "lang": "es",
      "value": "Condición de carrera en el plug-in SPICE (también conocido como spice-activex) para Internet Explorer en Red Hat Enterprise Virtualization (RHEV) Manager, en versiones anteriores a la 2.2.4, permite a usuarios locales crear una cierta tubería (pipe), y obtener privilegios, mediante vectores involucrados en el conocimiento del nombre de esta tubería junto con el uso de la función ImpersonateNamedPipeClient."
    }
  ],
  "lastModified": "2026-06-16T23:21:30.990",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redhat:spice-activex:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E08C77D3-DDAD-48A9-98C6-485415FEF25D"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_virtualization_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3BE45667-EC5D-41C3-89A5-7AC39BE70487",
              "versionEndIncluding": "2.2.3"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_virtualization_manager:2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33C28126-1A19-440E-9BD3-AA219146F738"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_virtualization_manager:2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BD61E07C-8CE1-4EC5-88FD-5410CB42D944"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}