← Back

CVE-2010-1906

nvd nist
Published: May 12, 2010Modified: Apr 29, 2026

JSON object

Loading...
7.2
Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 3.9 / Impact: 10.0
Source: NVD

Description

tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timestamp field to validate input to the \\.\pipe\__RepairService_pipe__company named pipe, which allows remote authenticated users to execute arbitrary code by obtaining the current time from (1) tcpip.sys or (2) an SMB2 service.

Affected (6)

4 products
Consona Dynamic Agent
Consona Repair Manager
Consona Subscriber Activation
Consona Subscriber Agent
Configuration A
6 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Consona
All versions
All versions
All versions
All versions
All versions
All versions
Running on/withPlatform Versions
Microsoft
Windows 7
All versions
Microsoft
Windows Vista
All versions

Related CWEs

References (12)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
PatchUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.