CVE-2023-28868: High severity ncp-e secure enterprise client vulnerability
Published Dec 9, 2023
·Updated
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by creating a symbolic link.
Affected Software
1 affected component
ncp-e Secure Enterprise Client<12.22
Event History
Dec 9, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-28868?
CVE-2023-28868 has a critical severity level due to its ability to allow attackers to delete arbitrary files.
2
How do I fix CVE-2023-28868?
To fix CVE-2023-28868, upgrade the NCP Secure Enterprise Client to version 12.22 or later.
3
What software is affected by CVE-2023-28868?
CVE-2023-28868 affects NCP Secure Enterprise Client versions prior to 12.22.
4
What type of vulnerability is CVE-2023-28868?
CVE-2023-28868 is a symbolic link vulnerability that can lead to unauthorized file deletion.
5
What can an attacker achieve with CVE-2023-28868?
An attacker can exploit CVE-2023-28868 to delete arbitrary files on the operating system.