Security Advisory

CVE-2010-2793

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2010-12-08 17:00:00
Last updated 2024-08-07 02:46:48
Assigner redhat
State PUBLISHED

Description

Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.