PT-2006-2004 · Ncp · Ncp Network Communication Secure Client
Publicado
2006-03-02
·
Atualizado
2018-10-18
·
CVE-2006-0965
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
NCP Network Communication Secure Client version 8.11 Build 146
Description
The issue allows local users to bypass security protections and configure privileged options. This is achieved by providing a long argument to
ncpmon.exe, which grants access to alternate privileged menus. The cause might be related to a buffer overflow.Recommendations
For version 8.11 Build 146, consider restricting access to
ncpmon.exe to prevent exploitation until a fix is available. As a temporary workaround, avoid using long arguments with ncpmon.exe to minimize the risk of bypassing security protections.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ncp Network Communication Secure Client