6.8
CVSSv2

CVE-2010-2793

Published: 08/12/2010 Updated: 16/01/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager prior to 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise virtualization manager 2.2

redhat enterprise virtualization manager 2.1

redhat spice-activex -

redhat enterprise virtualization manager