Vulnerabilities > CVE-2006-2086 - Remote Buffer Overflow vulnerability in Juniper SSL-VPN Client ActiveX Control

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
juniper
exploit available
metasploit

Summary

Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juniper NetScreen IVE device running IVE OS before 4.2r8.1, 5.0 before 5.0r6.1, 5.1 before 5.1r8, 5.2 before 5.2r4.1, or 5.3 before 5.3r2.1, allows remote attackers to execute arbitrary code via a long argument in the ProductName parameter.

Vulnerable Configurations

Part Description Count
Application
Juniper
1

Exploit-Db

descriptionJuniper SSL-VPN IVE JuniperSetupDLL.dll ActiveX Control Buffer Overflow. CVE-2006-2086. Remote exploit for windows platform
idEDB-ID:16568
last seen2016-02-02
modified2010-05-09
published2010-05-09
reportermetasploit
sourcehttps://www.exploit-db.com/download/16568/
titleJuniper SSL-VPN IVE JuniperSetupDLL.dll ActiveX Control Buffer Overflow

Metasploit

descriptionThis module exploits a stack buffer overflow in the JuniperSetupDLL.dll library which is called by the JuniperSetup.ocx ActiveX control, as part of the Juniper SSL-VPN (IVE) appliance. By specifying an overly long string to the ProductName object parameter, the stack is overwritten.
idMSF:EXPLOIT/WINDOWS/BROWSER/JUNIPER_SSLVPN_IVE_SETUPDLL
last seen2020-06-13
modified2017-11-08
published2009-07-30
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/browser/juniper_sslvpn_ive_setupdll.rb
titleJuniper SSL-VPN IVE JuniperSetupDLL.dll ActiveX Control Buffer Overflow

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/83003/juniper_sslvpn_ive_setupdll.rb.txt
idPACKETSTORM:83003
last seen2016-12-05
published2009-11-26
reporterpatrick
sourcehttps://packetstormsecurity.com/files/83003/Juniper-SSL-VPN-IVE-JuniperSetupDLL.dll-ActiveX-Control-Buffer-Overflow.html
titleJuniper SSL-VPN IVE JuniperSetupDLL.dll ActiveX Control Buffer Overflow