Back

MEDIUM

spice activex/spicec named pipe races

Published Dec 8, 2010

Description

Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 8, 2010
Updated Aug 7, 2024
Reserved Jul 22, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Dec 6, 2010