dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users to gain privileges via a crafted DNE_IOCTL DeviceIoControl request to the \\.\DNE device interface.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 00:53
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/30728 - Vendor Advisory | |
References | () http://secunia.com/advisories/30744 - Vendor Advisory | |
References | () http://secunia.com/advisories/30747 - Vendor Advisory | |
References | () http://secunia.com/advisories/30753 - | |
References | () http://securityreason.com/securityalert/4600 - | |
References | () http://support.citrix.com/article/CTX117751 - | |
References | () http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsm25860 - | |
References | () http://www.digit-labs.org/files/exploits/dne2000-call.c - | |
References | () http://www.kb.cert.org/vuls/id/858993 - US Government Resource | |
References | () http://www.securityfocus.com/bid/29772 - | |
References | () http://www.vupen.com/english/advisories/2008/1865 - | |
References | () http://www.vupen.com/english/advisories/2008/1866 - | |
References | () http://www.vupen.com/english/advisories/2008/1867 - | |
References | () http://www.vupen.com/english/advisories/2008/1868 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/43153 - | |
References | () https://www.exploit-db.com/exploits/5837 - |
Information
Published : 2008-11-18 00:30
Updated : 2024-11-21 00:53
NVD link : CVE-2008-5121
Mitre link : CVE-2008-5121
CVE.ORG link : CVE-2008-5121
JSON object : View
Products Affected
citrix
- deterministic_network_enhancer
safenet
- softremote_vpn_client
- highassurance_remote
bluecoat
- winproxy
cisco
- vpn_client
CWE
CWE-264
Permissions, Privileges, and Access Controls