CVE-2010-1906

tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timestamp field to validate input to the \\.\pipe\__RepairService_pipe__company named pipe, which allows remote authenticated users to execute arbitrary code by obtaining the current time from (1) tcpip.sys or (2) an SMB2 service.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:consona:consona_dynamic_agent:-:-:enterprise:*:*:*:*:*
cpe:2.3:a:consona:consona_dynamic_agent:-:-:marketing:*:*:*:*:*
cpe:2.3:a:consona:consona_subscriber_activation:*:*:*:*:*:*:*:*
cpe:2.3:a:consona:consona_subscriber_agent:*:*:*:*:*:*:*:*
cpe:2.3:a:consona:consona_dynamic_agent:-:-:support:*:*:*:*:*
cpe:2.3:a:consona:consona_repair_manager:*:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_7:*:*:*:*:*:*:*:*

Information

Published : 2010-05-12 04:46

Updated : 2018-10-10 12:57


NVD link : CVE-2010-1906

Mitre link : CVE-2010-1906


JSON object : View

CWE
CWE-310

Cryptographic Issues

Advertisement

dedicated server usa

Products Affected

microsoft

  • windows_7
  • windows_vista

consona

  • consona_subscriber_agent
  • consona_subscriber_activation
  • consona_repair_manager
  • consona_dynamic_agent