« Volver al listado

CVE-2010-5184

Estado: ModificadaMedia (6.2)—

Race condition in ZoneAlarm Extreme Security 9.1.507.000 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-5184",
  "cveTags": [
    {
      "tags": [
        "disputed"
      ],
      "sourceIdentifier": "cve@mitre.org"
    }
  ],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:H/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "HIGH",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 1.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-08-25T21:55:04.023",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2010-05/0026.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0066.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://countermeasures.trendmicro.eu/you-just-cant-trust-a-drunk/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://matousec.com/info/advisories/khobe-8.0-earthquake-for-windows-desktop-security-software.php",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://matousec.com/info/articles/khobe-8.0-earthquake-for-windows-desktop-security-software.php",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.f-secure.com/weblog/archives/00001949.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/67660",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/39924",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.theregister.co.uk/2010/05/07/argument_switch_av_bypass/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2010-05/0026.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0066.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://countermeasures.trendmicro.eu/you-just-cant-trust-a-drunk/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://matousec.com/info/advisories/khobe-8.0-earthquake-for-windows-desktop-security-software.php",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://matousec.com/info/articles/khobe-8.0-earthquake-for-windows-desktop-security-software.php",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.f-secure.com/weblog/archives/00001949.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/67660",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/39924",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.theregister.co.uk/2010/05/07/argument_switch_av_bypass/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-362"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Race condition in ZoneAlarm Extreme Security 9.1.507.000 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack.  NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute"
    },
    {
      "lang": "es",
      "value": "** EN DISPUTA ** Condición de carrera en ZoneAlarm Extreme Security v9.1.507.000 sobre Windows XP permite a usuarios locales evitar kernel-mode hook handlers, y ejecutar código peligroso que podría entre otras cosas ser bloqueado por un manejador pero no bloqueado por un detector de malware signature-based, a través de ciertos user-space cambios de memoria  durante la ejecución de hook-handler execution, también conocido como un ataque argument-switch o KHOBE. NOTA: esta  problema está en disputa por terceras partes."
    }
  ],
  "lastModified": "2026-06-16T23:26:16.683",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:checkpoint:zonealarm_extreme_security:9.1.507.000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CD802BAB-9667-4EBE-8975-01B2E043B127"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows_xp:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E61F1C9B-44AF-4B35-A7B2-948EEF7639BD"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}