#VU122145 Exposed dangerous method or function in NCP Secure Entry Client for Windows

 

#VU122145 Exposed dangerous method or function in NCP Secure Entry Client for Windows

Published: January 30, 2026


Vulnerability identifier: #VU122145
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-749
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
NCP Secure Entry Client for Windows
Software vendor:
NCP engineering GmbH

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to during certain actions, such as installation, update, or uninstallation of the VPN client, the command line windows (cmd.exe) are temporarily opened with the SYSTEM account privileges. A local user can interact with the opened command line directly and execute arbitrary code, leading to privilege escalation. 


Remediation

Install updates from vendor's website.

External links