Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager prior to 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
redhat enterprise virtualization manager 2.2 |
||
redhat enterprise virtualization manager 2.1 |
||
redhat spice-activex - |
||
redhat enterprise virtualization manager |