CVE-2010-5171: Race Condition
DISPUTED Race condition in Outpost Security Suite Pro 6.7.3.3063.452.0726 and 7.0.3330.505.1221 BETA on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-5171?
CVE-2010-5171 is considered a moderate severity vulnerability due to the potential for local users to bypass security measures.
How do I fix CVE-2010-5171?
To mitigate CVE-2010-5171, update to the latest version of the Agnitum Outpost Security Suite that resolves the race condition.
What systems are affected by CVE-2010-5171?
CVE-2010-5171 affects Agnitum Outpost Security Suite versions 6.7.3.3063.452.0726 and 7.0.3330.505.1221 BETA on Windows XP.
Can CVE-2010-5171 be exploited remotely?
CVE-2010-5171 cannot be exploited remotely as it requires local access to the vulnerable system.
What does CVE-2010-5171 allow an attacker to do?
CVE-2010-5171 allows local users to bypass kernel-mode hook handlers, enabling execution of potentially harmful code.