CVE-2013-10046 Details
Description
A local privilege escalation vulnerability exists in Agnitum Outpost Internet Security 8.1 that allows an unprivileged user to execute arbitrary code with SYSTEM privileges. The flaw resides in the acs.exe component, which exposes a named pipe that accepts unauthenticated commands. By exploiting a directory traversal weakness in the pipe protocol, an attacker can instruct the service to load a malicious DLL from a user-controlled location. The DLL is then executed in the context of the privileged service.
A local privilege escalation vulnerability has been identified in Agnitum Outpost Internet Security version 8.1. This vulnerability allows an unprivileged user to execute arbitrary code with SYSTEM privileges. The issue arises in the acs.exe component, which exposes a named pipe that accepts unauthenticated commands. Exploitation involves a directory traversal vulnerability in the pipe protocol, enabling an attacker to instruct the service to load a malicious DLL from a user-controlled location. The DLL is then executed in the context of the privileged service.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 1, 2025CISA-ADP
Assessed Aug 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Agnitum Outpost Internet Security | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Aug 1, 2025 | New CVE Received | [email protected] |
Volerion