First published: Mon Aug 02 2010(Updated: )
Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Virtualization Manager | <=2.2.3 | |
Red Hat Enterprise Virtualization Manager | =2.2 | |
Red Hat Enterprise Virtualization Manager | =2.1 | |
Red Hat Spice |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2793 is classified as a moderate severity vulnerability due to the potential for privilege escalation via a race condition.
To fix CVE-2010-2793, users should update to Red Hat Enterprise Virtualization Manager version 2.2.4 or later.
CVE-2010-2793 affects users of the SPICE ActiveX plug-in for Internet Explorer in certain versions of Red Hat Enterprise Virtualization Manager.
CVE-2010-2793 allows local users to exploit a race condition to create a named pipe, potentially gaining elevated privileges.
CVE-2010-2793 was disclosed in August 2010 as part of a security advisory related to Red Hat software products.