CVE-2010-2793
Red Hat Enterprise Virtualization <2.2.4 - Privilege Escalation
Title source: llmDescription
Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1024825
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=620355
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/45213
Vendor Advisory vendor-advisory
x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2010-0818.html
Scores
EPSS
0.0104
EPSS Percentile
59.6%
Details
CWE
CWE-362
Status
published
Products (4)
redhat/enterprise_virtualization_manager
2.1
redhat/enterprise_virtualization_manager
2.2
redhat/enterprise_virtualization_manager
< 2.2.3
redhat/spice-activex
Published
Dec 08, 2010
Tracked Since
Feb 18, 2026