CVE-2010-1906
12.05.2010, 11:46
tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timestamp field to validate input to the \\.\pipe\__RepairService_pipe__company named pipe, which allows remote authenticated users to execute arbitrary code by obtaining the current time from (1) tcpip.sys or (2) an SMB2 service.Enginsight
Vendor | Product | Version |
---|---|---|
consona | consona_dynamic_agent | - |
consona | consona_dynamic_agent | - |
consona | consona_dynamic_agent | - |
consona | consona_repair_manager | * |
consona | consona_subscriber_activation | * |
consona | consona_subscriber_agent | * |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References