Vigil@nce - Junos Pulse Secure Access Service: privilege escalation via Linux Network Connect
March 2014 by Vigil@nce
This bulletin was written by Vigil@nce : http://vigilance.fr/offer
SYNTHESIS OF THE VULNERABILITY
A local attacker can use Linux Network Connect of Junos Pulse
Secure Access Service, in order to escalate his privileges.
Impacted products: IVE OS, Junos Pulse, Juniper SA
Severity: 2/4
Creation date: 12/03/2014
DESCRIPTION OF THE VULNERABILITY
The Linux Network Connect product is installed on Linux computers,
to access to the SSL VPN.
However, a local attacker can use Linux Network Connect to gain
root privileges. Technical details are unknown.
A local attacker can therefore use Linux Network Connect of Junos
Pulse Secure Access Service, in order to escalate his privileges.
ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN