| PROBLEM: | The Deterministic Network driver contains a privilege escalation vulnerability, which can allow a local attacker to execute code with kernel privileges. |
| PLATFORM: | Deterministic Network |
| DAMAGE: | Execute code. |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. A local attakcer may be able to execute code with windows kernel privileges. |
| CVSS 2 BASE SCORE: TEMPORAL SCORE: VECTOR: |
6.6 5.5 (AV:L/AC:L/Au:N/C:C/I:C/A:N/E:F/RL:OF/RC:C) |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/s-322.shtml |
| ORIGINAL BULLETIN: | http://www.kb.cert.org/vuls/id/858993 |
[***** Start US-CERT Vulnerability Note VU#858993 *****]
This issue is addressed in dne2000.sys version 3.21.12.17902. This driver is available from the DNE support page.
Cisco Windows VPN Client users should install version 5.0.03.0530, as specified in Cisco Support document CSCsm25860.
For other products that provide the DNE driver, please check with the vendor for updates.
| Vendor | Status | Date Updated |
|---|---|---|
| Blue Coat Systems | Vulnerable | 19-Jun-2008 |
| Cisco Systems, Inc. | Vulnerable | 18-Jun-2008 |
| Deterministic Networks, Inc | Vulnerable | 18-Jun-2008 |
| SafeNet | Vulnerable | 19-Jun-2008 |
http://www.digit-labs.org/files/exploits/dne2000-call.c
http://www.deterministicnetworks.com/support/dnesupport.asp
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsm25860
http://secunia.com/advisories/30728/
http://secunia.com/advisories/30753/
http://secunia.com/advisories/30744/
http://secunia.com/advisories/30747/
This vulnerability was reported by mu-b at Digit-Labs.
This document was written by Will Dormann.
| Date Public | 06/17/2008 |
| Date First Published | 06/18/2008 11:16:29 AM |
| Date Last Updated | 06/19/2008 |
| CERT Advisory | |
| CVE Name | |
| US-CERT Technical Alerts | |
| Metric | 22.50 |
| Document Revision | 6 |
[***** End US-CERT Vulnerability Note VU#858993 *****]
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org