First published: Thu Sep 06 2012(Updated: )
Multiple untrusted search path vulnerabilities in NCP Secure Enterprise Client before 9.21 Build 68, Secure Entry Client before 9.23 Build 18, and Secure Client - Juniper Edition before 9.23 Build 18 allow local users to gain privileges via a Trojan horse (1) dvccsabase002.dll, (2) conman.dll, (3) kmpapi32.dll, or (4) ncpmon2.dll file in the current working directory, as demonstrated by a directory that contains a .pcf or .spd file. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ncp-e Secure Client | <=9.23 | |
Ncp-e Secure Enterprise Client | <=9.21 | |
Ncp-e Secure Entry Client | <=9.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-5203 is considered a high severity vulnerability due to its potential to allow local users to gain elevated privileges through untrusted search paths.
To fix CVE-2010-5203, update NCP Secure Enterprise Client to version 9.21 Build 68 or later, and Secure Entry Client and Secure Client - Juniper Edition to version 9.23 Build 18 or later.
CVE-2010-5203 affects users of NCP Secure Enterprise Client versions prior to 9.21 Build 68, Secure Entry Client versions prior to 9.23 Build 18, and Secure Client - Juniper Edition versions before 9.23 Build 18.
CVE-2010-5203 contains multiple untrusted search path vulnerabilities that can be exploited via malicious DLL files.
No, CVE-2010-5203 requires local access for exploitation, as it involves executing Trojan horse DLLs on the system.