Vulnerability record · CVE-2008-0935 · published 25 February 2008
CVE-2008-0935: Novell iPrint Client ActiveX control stack buffer overflow
Novell · Iprint
The Novell iPrint Control ActiveX control (ienipp.ocx) in iPrint Client before 4.34 contains a stack-based buffer overflow. A long argument passed to the ExecuteRequest method overflows a stack buffer, allowing remote code execution. Because the control is loaded in the browser, any user who visits a malicious page with the control installed is exposed.
Description
Stack-based buffer overflow in the Novell iPrint Control ActiveX control in ienipp.ocx in Novell iPrint Client before 4.34 allows remote attackers to execute arbitrary code via a long argument to the ExecuteRequest method.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote unauthenticated code execution with full impact and a very high EPSS score, though exploitation requires the victim to load the ActiveX control in a browser.
What it is
The Novell iPrint Control ActiveX control (ienipp.ocx) in iPrint Client before 4.34 contains a stack-based buffer overflow. A long argument passed to the ExecuteRequest method overflows a stack buffer, allowing remote code execution. Because the control is loaded in the browser, any user who visits a malicious page with the control installed is exposed.
Impact
An attacker can execute arbitrary code in the context of the logged-on user, leading to full compromise of the workstation. Given the CVSS 2.0 vector (C:C/I:C/A:C), confidentiality, integrity and availability are all fully impacted.
Attack surface
Reached over the network through a web page that instantiates the iPrint ActiveX control and calls ExecuteRequest with an oversized argument. No authentication is required (Au:N), but the victim must have the vulnerable control installed and interact with the malicious page, so user interaction is effectively required.
Exploitation
The record is not listed in CISA KEV and no ransomware usage is documented. EPSS is high (0.6514, 99.2nd percentile), indicating a strong likelihood of exploitation activity, but no public exploit reference is tagged in the supplied data.
What to do
- Upgrade Novell iPrint Client to version 4.34 or later using the vendor patch referenced in the advisory.
- If immediate patching is not possible, disable or remove the iPrint Control ActiveX control (ienipp.ocx) and block its CLSID via Internet Explorer kill-bit or equivalent browser policy.
- Restrict browsing to trusted sites and enforce ActiveX controls to prompt or be disabled in the browser security zones.
- Remove the iPrint Client from systems that do not require it to reduce the exposed attack surface.
Detection
- Monitor for processes loading ienipp.ocx, especially from browser processes such as iexplore.exe.
- Hunt for crashes or exceptions in iexplore.exe or the iPrint control that correlate with visits to untrusted web pages.
- Review proxy and web logs for pages that embed the iPrint ActiveX control or reference its CLSID.
- Check endpoint inventory for iPrint Client versions below 4.34 and flag them for remediation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-0935 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-0935), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.