Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-28872


Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\Temp\NcpSupport* location.


Published

2023-12-25T07:15:07.893

Last Modified

2024-11-21T07:56:12.233

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-59

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ncp-e secure_enterprise_client < 13.10 Yes

References