#VU122145 Exposed dangerous method or function in NCP Secure Entry Client for Windows
Published: January 30, 2026
NCP Secure Entry Client for Windows
NCP engineering GmbH
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to during certain actions, such as installation, update, or uninstallation of the VPN client, the command line windows (cmd.exe) are temporarily opened with the SYSTEM account privileges. A local user can interact with the opened command line directly and execute arbitrary code, leading to privilege escalation.