First published: Wed Aug 28 2013(Updated: )
Unquoted Windows search path vulnerability in the Red Hat Enterprise Virtualization Application Provisioning Tool (RHEV-APT) in the rhev-guest-tools-iso package 3.2 allows local users to gain privileges via a Trojan horse application.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Virtualization | =3.0 | |
Red Hat Enterprise Virtualization | =3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2176 is considered a high severity vulnerability due to its potential for local privilege escalation.
To mitigate CVE-2013-2176, update the Red Hat Enterprise Virtualization Application Provisioning Tool to versions 3.2 or later.
CVE-2013-2176 affects Red Hat Enterprise Virtualization versions 3.0 and 3.2.
CVE-2013-2176 can be exploited by local users executing a Trojan horse application due to an unquoted search path vulnerability.
Any local user with access to the affected system can potentially exploit CVE-2013-2176 to gain elevated privileges.