cbcvebase.
CVE-2008-2908
published 2008-06-30

CVE-2008-2908: Multiple stack-based buffer overflows in a certain ActiveX control in ienipp.ocx in Novell iPrint Client for Windows before 4.36 allow remote attackers to…

PriorityP354critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
35.42%
98.3th percentile
Multiple stack-based buffer overflows in a certain ActiveX control in ienipp.ocx in Novell iPrint Client for Windows before 4.36 allow remote attackers to execute arbitrary code via a long value of the (1) operation, (2) printer-url, or (3) target-frame parameter. NOTE: some of these details are obtained from third party information.

Affected

1 ranges
VendorProductVersion rangeFixed in
novelliprint_client<= 4.35

Detection & IOCsextracted from sources · hover to see the quote

filenameienipp.ocx
other0x0A0A0A0A
  • ·The Metasploit module targets specifically Novell iPrint Client version 4.34; the vulnerability affects all versions before 4.36. The fixed version is 4.36 or later.
  • ·The module sets EXITFUNC to 'process', meaning the exploit terminates the browser process on exit rather than using a thread-safe exit — detections based on abnormal iexplore.exe termination may be relevant.
  • ·JavaScript variable names in the exploit HTML are randomized, limiting static string-based detection of the malicious page.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.