CVE-2010-0923

Race condition in workspace/krunner/lock/lockdlg.cc in the KRunner lock module in kdebase in KDE SC 4.4.0 allows physically proximate attackers to bypass KScreenSaver screen locking and access an unattended workstation by pressing the Enter key at a certain time, related to multiple forked processes.

Published: 2010-03-03 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2010-0923 is rated Low Risk (34.7/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.28%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2010-0923

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.04% 0.28% +0.24%
2 2025-03-17 0.06% 0.04% -0.03%
3 2024-09-17 0.06%

Full EPSS history (6 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2010-0923

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.9 2.0 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
3.4 10.0 [email protected]

Weakness enumeration for CVE-2010-0923

OS Trackers for CVE-2010-0923

vendor priority summary link
redhat high https://access.redhat.com/security/cve/CVE-2010-0923
ubuntu medium CVE-2010-0923 medium priority: Ubuntu including 1 source packages (kdebase-workspace), 6 status rows across 6 suites (dapper, hardy, intrepid, jaunty, karmic, upstream): not-affected 5, released 1. https://ubuntu.com/security/CVE-2010-0923

Affected software / configurations for CVE-2010-0923

Vendor Product Version Raw CPE
kde kde_sc 4.4.0 cpe:2.3:a:kde:kde_sc:4.4.0:*:*:*:*:*:*:*

References for CVE-2010-0923

URL Tags
http://bugs.kde.org/show_bug.cgi?id=226449
http://marc.info/?l=oss-security&m=126598163422670&w=2
http://marc.info/?l=oss-security&m=126599909614401&w=2
http://marc.info/?l=oss-security&m=126600468622421&w=2
http://secunia.com/advisories/38600 Vendor Advisory
http://securitytracker.com/id?1023641
http://websvn.kde.org/?revision=1089213&view=revision Patch
http://websvn.kde.org/?view=revision&revision=1089241 Patch
http://websvn.kde.org/trunk/KDE/kdebase/workspace/krunner/lock/lockdlg.cc?r1=1089213&r2=1089212&pathrev=1089213
http://www.kde.org/info/security/advisory-20100217-1.txt
http://www.openwall.com/lists/oss-security/2010/02/17/3
http://www.vupen.com/english/advisories/2010/0409 Patch Vendor Advisory
https://bugs.kde.org/show_bug.cgi?id=217882
https://bugzilla.novell.com/show_bug.cgi?id=579280
cvelogic Threat Intelligence