PT-2012-1414 · Ncp · Ncp Secure Entry Client+2

Published

2012-09-06

·

Updated

2012-09-06

·

CVE-2010-5203

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NCP Secure Enterprise Client versions prior to 9.21 Build 68 NCP Secure Entry Client versions prior to 9.23 Build 18 NCP Secure Client - Juniper Edition versions prior to 9.23 Build 18
Description The issue allows local users to gain privileges via a Trojan horse dvccsabase002.dll, conman.dll, kmpapi32.dll, or ncpmon2.dll file in the current working directory. This can be demonstrated by a directory that contains a .pcf or .spd file.
Recommendations For NCP Secure Enterprise Client versions prior to 9.21 Build 68, update to version 9.21 Build 68 or later. For NCP Secure Entry Client versions prior to 9.23 Build 18, update to version 9.23 Build 18 or later. For NCP Secure Client - Juniper Edition versions prior to 9.23 Build 18, update to version 9.23 Build 18 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-5203

Affected Products

Ncp Secure Client - Juniper Edition
Ncp Secure Enterprise Client
Ncp Secure Entry Client