cbcvebase.
CVE-2010-2793
published 2010-12-08

CVE-2010-2793: Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local…

PriorityP426medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.04%
59.9th percentile
Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.

Affected

3 ranges
VendorProductVersion rangeFixed in
redhatenterprise_virtualization_manager<= 2.2.3
redhatenterprise_virtualization_manager
redhatenterprise_virtualization_manager

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.