Vulnerability Description
The ncprwsnt service in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to execute arbitrary code by modifying the connect.bat script, which is automatically executed by the service after a connection is established.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ncp Network Communications | Secure Client | 8.11_build_146 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html
- http://secunia.com/advisories/19082
- http://securityreason.com/securityalert/524
- http://www.securityfocus.com/archive/1/426480/100/0/threaded
- http://www.securityfocus.com/bid/16906
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25251
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html
- http://secunia.com/advisories/19082
- http://securityreason.com/securityalert/524
- http://www.securityfocus.com/archive/1/426480/100/0/threaded
- http://www.securityfocus.com/bid/16906
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25251
FAQ
What is CVE-2006-0968?
CVE-2006-0968 is a vulnerability with a CVSS score of 7.2 (HIGH). The ncprwsnt service in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to execute arbitrary code by modifying the connect.bat script, which is ...
How severe is CVE-2006-0968?
CVE-2006-0968 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-0968?
Check the references section above for vendor advisories and patch information. Affected products include: Ncp Network Communications Secure Client.