First published: Tue Nov 18 2008(Updated: )
dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users to gain privileges via a crafted DNE_IOCTL DeviceIoControl request to the \\.\DNE device interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix Deterministic Network Enhancer | =2.21.7.223 | |
Citrix Deterministic Network Enhancer | =3.21.7.17464 | |
Bluecoat Winproxy | ||
Cisco VPN Client | ||
Safenet Highassurance Remote | ||
SafeNet SoftRemote VPN Client |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5121 has a medium severity rating due to the potential for local users to gain elevated privileges.
To fix CVE-2008-5121, you should update to the latest version of Citrix Deterministic Network Enhancer.
CVE-2008-5121 affects Citrix Deterministic Network Enhancer versions 2.21.7.233 through 3.21.7.17464.
Yes, local users can exploit CVE-2008-5121 by sending a crafted DNE_IOCTL DeviceIoControl request.
Yes, there are known exploits that take advantage of the vulnerability in CVE-2008-5121.