CVE-2010-4664
HIGHCVSS 8.8/10EPSS 1.21%
Last modified
CVE-2010-4664 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.. EPSS estimates a 1.21% chance of exploitation in the next 30 days.
Description
In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Consolekit Project | Consolekit | < 0.4.2 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
| Redhat | Enterprise Linux | 6.0 |
References
- https://access.redhat.com/security/cve/cve-2010-4664Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4664Issue Tracking, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2010-4664Third Party Advisory
- https://access.redhat.com/security/cve/cve-2010-4664Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4664Issue Tracking, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2010-4664Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-4664?
In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.
How severe is CVE-2010-4664?
CVE-2010-4664 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 1.21% probability of exploitation in the next 30 days.
How do I fix CVE-2010-4664?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-4658statusnet through 2010 allows attackers to spoof syslog mess…5.3
- CVE-2010-4659Cross-site scripting (XSS) vulnerability in statusnet throug…6.1
- CVE-2010-4660Unspecified vulnerability in statusnet through 2010 due to t…9.8
- CVE-2010-4661udisks before 1.0.3 allows a local user to load arbitrary Li…7.8
- CVE-2010-4662PmWiki before 2.2.21 has XSS.6.1
- CVE-2010-4663Unspecified vulnerability in the News module in CMS Made Sim…
- CVE-2010-4665Integer overflow in the ReadDirectory function in tiffdump.c…
- CVE-2010-4666Buffer overflow in libarchive 3.0 pre-release code allows re…
- CVE-2010-4667Cross-site scripting (XSS) vulnerability in Coppermine Photo…
- CVE-2010-4668The blk_rq_map_user_iov function in block/blk-map.c in the L…
- CVE-2010-4669The Neighbor Discovery (ND) protocol implementation in the I…
- CVE-2010-4670The Neighbor Discovery (ND) protocol implementation in the I…
Are you affected by CVE-2010-4664?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
