NCP Secure Entry Client 9.2 contains an unquoted service path vulnerability in multiple Windows services that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted paths in services like ncprwsnt, rwsrsu, ncpclcfg, and NcpSec to inject malicious code that would execute with LocalSystem privileges during service startup.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Feb 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ncp-e
Ncp-e ncp Secure Entry Client |
|
| Vendors & Products |
Ncp-e
Ncp-e ncp Secure Entry Client |
Wed, 04 Feb 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NCP Secure Entry Client 9.2 contains an unquoted service path vulnerability in multiple Windows services that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted paths in services like ncprwsnt, rwsrsu, ncpclcfg, and NcpSec to inject malicious code that would execute with LocalSystem privileges during service startup. | |
| Title | NCP_Secure_Entry_Client 9.2 - Unquoted Service Paths | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-04T23:15:52.910Z
Updated: 2026-02-05T17:45:42.726Z
Reserved: 2026-01-06T16:07:08.527Z
Link: CVE-2019-25281
Updated: 2026-02-05T17:45:39.675Z
Status : Awaiting Analysis
Published: 2026-02-05T00:15:52.417
Modified: 2026-02-05T14:57:20.563
Link: CVE-2019-25281
No data.
ReportizFlow