PT-2006-2004 · Ncp · Ncp Network Communication Secure Client
Published
2006-03-02
·
Updated
2018-10-18
·
CVE-2006-0965
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
NCP Network Communication Secure Client version 8.11 Build 146
Description
The issue allows local users to bypass security protections and configure privileged options. This is achieved by providing a long argument to
ncpmon.exe, which grants access to alternate privileged menus. The cause might be related to a buffer overflow.Recommendations
For version 8.11 Build 146, consider restricting access to
ncpmon.exe to prevent exploitation until a fix is available. As a temporary workaround, avoid using long arguments with ncpmon.exe to minimize the risk of bypassing security protections.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ncp Network Communication Secure Client