PT-2006-2004 · Ncp · Ncp Network Communication Secure Client

Published

2006-03-02

·

Updated

2018-10-18

·

CVE-2006-0965

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions NCP Network Communication Secure Client version 8.11 Build 146
Description The issue allows local users to bypass security protections and configure privileged options. This is achieved by providing a long argument to ncpmon.exe, which grants access to alternate privileged menus. The cause might be related to a buffer overflow.
Recommendations For version 8.11 Build 146, consider restricting access to ncpmon.exe to prevent exploitation until a fix is available. As a temporary workaround, avoid using long arguments with ncpmon.exe to minimize the risk of bypassing security protections.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0965

Affected Products

Ncp Network Communication Secure Client