Oracle VM CVE-2010-3585 Remote Code Execution Vulnerability
BID:44047
Info
Oracle VM CVE-2010-3585 Remote Code Execution Vulnerability
| Bugtraq ID: | 44047 |
| Class: | Unknown |
| CVE: |
CVE-2010-3585 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 13 2010 12:00AM |
| Updated: | Jun 14 2011 04:10PM |
| Credit: | Onapsis Research Labs |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Oracle VM CVE-2010-3585 Remote Code Execution Vulnerability
Oracle VM is prone to a remote code-execution vulnerability.
The vulnerability can be exploited over the 'xmlrpc, tcp/ip' protocol. The 'ovs-agent' sub component is affected.
Successfully exploiting this issue will allow attackers to execute arbitrary code with elevated privileges, resulting in the complete compromise of the affected computer.
This vulnerability affects the following supported versions:
2.2.1
Oracle VM is prone to a remote code-execution vulnerability.
The vulnerability can be exploited over the 'xmlrpc, tcp/ip' protocol. The 'ovs-agent' sub component is affected.
Successfully exploiting this issue will allow attackers to execute arbitrary code with elevated privileges, resulting in the complete compromise of the affected computer.
This vulnerability affects the following supported versions:
2.2.1
Exploit / POC
Oracle VM CVE-2010-3585 Remote Code Execution Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Oracle VM CVE-2010-3585 Remote Code Execution Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle VM CVE-2010-3585 Remote Code Execution Vulnerability
References:
References: