In association with heise online

27 May 2013, 12:01

0-days in Novell Client for Windows

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

Novell logo Those users who are still using Novell Client for Windows should look around for alternatives. In recent weeks, at least two 0-day exploits for the kernel driver have surfaced on the internet. The security firm eEye has documented the issues with the ids 20130510 and 20130522.

The first hole, 20130510, relates to the old Novell Client 4.91 SP5 IR1 for Windows XP/2003, while the second, 20130522, concerns Novell Client 2 SP3 for Windows 7 and Windows 8. Both only offer attackers local code execution within the kernel but that could be used by attackers to disguise a previous compromise as part of digging in further on a system. There are, so far, no patches or usable workarounds for either flaw.


Print Version | Send by email | Permalink:

  • July's Community Calendar

The H Open

The H Security

The H Developer

The H Internet Toolkit