Vulnerability Details CVE-2023-28872
Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\Temp\NcpSupport* location.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 36.3%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2023-28872
-
cpe:2.3:a:ncp-e:secure_enterprise_client:-
-
cpe:2.3:a:ncp-e:secure_enterprise_client:10.14
-
cpe:2.3:a:ncp-e:secure_enterprise_client:10.15
-
cpe:2.3:a:ncp-e:secure_enterprise_client:12.22