CVE-2013-2152: High severity red hat enterprise virtualization vulnerability
An unquoted search path flaw was found in the way Spice service for Windows was installed into the system.
A local unprivileged user could use this flaw to increase their privileges.
References:
http://cwe.mitre.org/data/definitions/428.html
Other sources
Unquoted Windows search path vulnerability in the SPICE service, as used in Red Hat Enterprise Virtualization (RHEV) 3.2, allows local users to gain privileges via a crafted application in an unspecified folder.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2152?
CVE-2013-2152 is considered to have a moderate severity due to its potential for local privilege escalation.
How do I fix CVE-2013-2152?
To fix CVE-2013-2152, ensure that the Spice service is properly quoted in the installation path to prevent unprivileged access.
Who is affected by CVE-2013-2152?
CVE-2013-2152 affects systems running Red Hat Enterprise Virtualization version 3.2 and allows local unprivileged users to escalate privileges.
What is the impact of CVE-2013-2152?
The impact of CVE-2013-2152 allows a local unprivileged user to execute arbitrary code with elevated privileges.
Is there a patch available for CVE-2013-2152?
Yes, patches for CVE-2013-2152 are available in the errata from Red Hat for the affected versions.