CVE-2013-2152Unquoted Search Path or Element in Redhat Enterprise Virtualization

Severity
7.2HIGHNVD
EPSS
0.1%
top 78.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 21
Latest updateMay 17

Description

Unquoted Windows search path vulnerability in the SPICE service, as used in Red Hat Enterprise Virtualization (RHEV) 3.2, allows local users to gain privileges via a crafted application in an unspecified folder.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-2r5w-8r8w-hxph: Unquoted Windows search path vulnerability in the SPICE service, as used in Red Hat Enterprise Virtualization (RHEV) 32022-05-17
CVEList
CVE-2013-2152: Unquoted Windows search path vulnerability in the SPICE service, as used in Red Hat Enterprise Virtualization (RHEV) 32014-01-21

📋Vendor Advisories

1
Red Hat
rhevm: spice service unquoted search path2013-06-10

💬Community

1
Bugzilla
CVE-2013-2152 rhevm: spice service unquoted search path2013-06-05
CVE-2013-2152 — Unquoted Search Path or Element | cvebase