Product Affected

Juniper NS-Remote VPN Client 9.0r3 and older versions are affected. The latest Juniper NS-Remote VPN Client 9.0r4 is not affected.
Low

Problem

A security vulnerability in NS-Remote (specifically the Deterministic Network Enhancer driver) has been reported which allows a local process to gain elevated privileges. The vulnerability exists in the dne2000.sys driver. By making a certain ioctl to the DNE device driver, it is possible to execute code with windows kernel privileges. This vulnerability is only exploitable locally.

Questions about this vulnerability should be sent to [email protected] .

Solution

This issue is resolved in the NS-Remote VPN Client version 9.0r4.

Customers are recommended to download and install NS-Remote VPN Client version 9.0r4. Should you have difficulty downloading this version, please contact the Juniper Support Center.

Severity Assessment

By making a certain ioctl to the DNE device driver, it is possible to execute code with windows kernel privileges. This vulnerability is only exploitable locally.

Related Information