tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timestamp field to validate input to the \\.\pipe\__RepairService_pipe__company named pipe, which allows remote authenticated users to execute arbitrary code by obtaining the current time from (1) tcpip.sys or (2) an SMB2 service.
2010-05-12T11:46:31.580
2025-04-11T00:51:21.963
Deferred
CVSSv2: 7.2 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | consona | consona_dynamic_agent | - | Yes |
Application | consona | consona_dynamic_agent | - | Yes |
Application | consona | consona_dynamic_agent | - | Yes |
Application | consona | consona_repair_manager | * | Yes |
Application | consona | consona_subscriber_activation | * | Yes |
Application | consona | consona_subscriber_agent | * | Yes |
Operating System | microsoft | windows_7 | * | No |
Operating System | microsoft | windows_vista | * | No |