Overview
- Description
- The WebSphere MQ XA 5.3 before FP13 and 6.0.x before 6.0.2.1 client for Windows, when running in an MTS or a COM+ environment, grants the PROCESS_DUP_HANDLE privilege to the Everyone group upon connection to a queue manager, which allows local users to duplicate an arbitrary handle and possibly hijack an arbitrary process.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 3.3
- Impact score
- 4.9
- Exploitability score
- 3.4
- Vector string
- AV:L/AC:M/Au:N/C:N/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-264
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:websphere_mq:*:fp_13:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "68907115-7F32-4C32-A2AC-B7C9E4F0BA57", "versionEndIncluding": "5.3" }, { "criteria": "cpe:2.3:a:ibm:websphere_mq:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E9A2214B-937A-4138-A39F-2980A61922DA", "versionEndIncluding": "6.0.2.0" } ], "operator": "OR" } ] } ]