A security vulnerability in NS-Remote (specifically the Deterministic Network Enhancer driver) has been reported which allows a local process to gain elevated privileges. The vulnerability exists in the dne2000.sys driver. By making a certain ioctl to the DNE device driver, it is possible to execute code with windows kernel privileges. This vulnerability is only exploitable locally. Questions about this vulnerability should be sent to [email protected] .
This issue is resolved in the NS-Remote VPN Client version 9.0r4.
Customers are recommended to download and install NS-Remote VPN Client version 9.0r4. Should you have difficulty downloading this version, please contact the Juniper Support Center.