CVE-2010-2793

Red Hat Enterprise Virtualization <2.2.4 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1024825
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=620355
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/45213
Vendor Advisory vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2010-0818.html

Scores

EPSS 0.0104
EPSS Percentile 59.6%

Details

CWE
CWE-362
Status published
Products (4)
redhat/enterprise_virtualization_manager 2.1
redhat/enterprise_virtualization_manager 2.2
redhat/enterprise_virtualization_manager < 2.2.3
redhat/spice-activex
Published Dec 08, 2010
Tracked Since Feb 18, 2026