Tracker / CVE-2010-1906
CVE-2010-1906
High 7.2
tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timestamp field to validate input to the \\.\pipe\__RepairService_pipe__company named pipe, which allows remote authenticated users to execute arbitrary code by obtaining the current time from (1) tcpip.sys or (2) an SMB2 service.
Affected products and versions
| consona | consona_dynamic_agent |
|---|---|
| consona | consona_repair_manager |
| consona | consona_subscriber_activation |
| consona | consona_subscriber_agent |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.