CVE-2008-5121
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 1.1%
exploitation probability
1.1%top 37% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users to gain privileges via a crafted DNE_IOCTL DeviceIoControl request to the \\.\DNE device interface.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
cve_reference✓ VexDay Proofwww.exploit-db.com/exploits/5837⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://secunia.com/advisories/30728http://secunia.com/advisories/30744http://secunia.com/advisories/30747http://secunia.com/advisories/30753http://securityreason.com/securityalert/4600https://exchange.xforce.ibmcloud.com/vulnerabilities/43153http://support.citrix.com/article/CTX117751https://www.exploit-db.com/exploits/5837http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsm25860http://www.digit-labs.org/files/exploits/dne2000-call.chttp://www.kb.cert.org/vuls/id/858993http://www.securityfocus.com/bid/29772