Deterministic Network Enhancer 'dne2000.sys' Local Privilege Escalation Vulnerability

Deterministic Network Enhancer (DNE) is prone to a local privilege-escalation vulnerability because it fails to adequately sanitize user-supplied data.

Attackers can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successful attacks will completely compromise affected computers.

DNE 'dne2000.sys' 2.21.7.233 to 3.21.8 are vulnerable; other versions may also be affected.

Affected versions of the 'dne2000.sys' driver are bundled with the following products:

SafeNet HighAssurance Remote and SoftRemote
Cisco VPN Client
WinProxy

Other products may also be affected.


 

Privacy Statement
Copyright 2010, SecurityFocus