CVE-2019-25281 – NCP_Secure_Entry_Client 9.2 – Unquoted Service Paths

CVE ID : CVE-2019-25281

Published : Feb. 5, 2026, 12:15 a.m. | 1 hour, 3 minutes ago

Description : NCP Secure Entry Client 9.2 contains an unquoted service path vulnerability in multiple Windows services that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted paths in services like ncprwsnt, rwsrsu, ncpclcfg, and NcpSec to inject malicious code that would execute with LocalSystem privileges during service startup.

Severity: 8.5 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… 

نوشته های مشابه