CVE-2008-5121

dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users to gain privileges via a crafted DNE_IOCTL DeviceIoControl request to the \\.\DNE device interface.
References
Link Resource
http://secunia.com/advisories/30728 Vendor Advisory
http://secunia.com/advisories/30744 Vendor Advisory
http://secunia.com/advisories/30747 Vendor Advisory
http://secunia.com/advisories/30753
http://securityreason.com/securityalert/4600
http://support.citrix.com/article/CTX117751
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsm25860
http://www.digit-labs.org/files/exploits/dne2000-call.c
http://www.kb.cert.org/vuls/id/858993 US Government Resource
http://www.securityfocus.com/bid/29772
http://www.vupen.com/english/advisories/2008/1865
http://www.vupen.com/english/advisories/2008/1866
http://www.vupen.com/english/advisories/2008/1867
http://www.vupen.com/english/advisories/2008/1868
https://exchange.xforce.ibmcloud.com/vulnerabilities/43153
https://www.exploit-db.com/exploits/5837
http://secunia.com/advisories/30728 Vendor Advisory
http://secunia.com/advisories/30744 Vendor Advisory
http://secunia.com/advisories/30747 Vendor Advisory
http://secunia.com/advisories/30753
http://securityreason.com/securityalert/4600
http://support.citrix.com/article/CTX117751
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsm25860
http://www.digit-labs.org/files/exploits/dne2000-call.c
http://www.kb.cert.org/vuls/id/858993 US Government Resource
http://www.securityfocus.com/bid/29772
http://www.vupen.com/english/advisories/2008/1865
http://www.vupen.com/english/advisories/2008/1866
http://www.vupen.com/english/advisories/2008/1867
http://www.vupen.com/english/advisories/2008/1868
https://exchange.xforce.ibmcloud.com/vulnerabilities/43153
https://www.exploit-db.com/exploits/5837
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:citrix:deterministic_network_enhancer:2.21.7.223:*:*:*:*:*:*:*
cpe:2.3:a:citrix:deterministic_network_enhancer:3.21.7.17464:*:*:*:*:*:*:*
OR cpe:2.3:a:bluecoat:winproxy:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:vpn_client:*:*:*:*:*:*:*:*
cpe:2.3:a:safenet:highassurance_remote:*:*:*:*:*:*:*:*
cpe:2.3:a:safenet:softremote_vpn_client:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:53

Type Values Removed Values Added
References () http://secunia.com/advisories/30728 - Vendor Advisory () http://secunia.com/advisories/30728 - Vendor Advisory
References () http://secunia.com/advisories/30744 - Vendor Advisory () http://secunia.com/advisories/30744 - Vendor Advisory
References () http://secunia.com/advisories/30747 - Vendor Advisory () http://secunia.com/advisories/30747 - Vendor Advisory
References () http://secunia.com/advisories/30753 - () http://secunia.com/advisories/30753 -
References () http://securityreason.com/securityalert/4600 - () http://securityreason.com/securityalert/4600 -
References () http://support.citrix.com/article/CTX117751 - () http://support.citrix.com/article/CTX117751 -
References () http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsm25860 - () http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsm25860 -
References () http://www.digit-labs.org/files/exploits/dne2000-call.c - () http://www.digit-labs.org/files/exploits/dne2000-call.c -
References () http://www.kb.cert.org/vuls/id/858993 - US Government Resource () http://www.kb.cert.org/vuls/id/858993 - US Government Resource
References () http://www.securityfocus.com/bid/29772 - () http://www.securityfocus.com/bid/29772 -
References () http://www.vupen.com/english/advisories/2008/1865 - () http://www.vupen.com/english/advisories/2008/1865 -
References () http://www.vupen.com/english/advisories/2008/1866 - () http://www.vupen.com/english/advisories/2008/1866 -
References () http://www.vupen.com/english/advisories/2008/1867 - () http://www.vupen.com/english/advisories/2008/1867 -
References () http://www.vupen.com/english/advisories/2008/1868 - () http://www.vupen.com/english/advisories/2008/1868 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/43153 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/43153 -
References () https://www.exploit-db.com/exploits/5837 - () https://www.exploit-db.com/exploits/5837 -

Information

Published : 2008-11-18 00:30

Updated : 2024-11-21 00:53


NVD link : CVE-2008-5121

Mitre link : CVE-2008-5121

CVE.ORG link : CVE-2008-5121


JSON object : View

Products Affected

citrix

  • deterministic_network_enhancer

safenet

  • softremote_vpn_client
  • highassurance_remote

bluecoat

  • winproxy

cisco

  • vpn_client
CWE
CWE-264

Permissions, Privileges, and Access Controls