CVE-2023-28871: Medium severity ncp-e secure enterprise client vulnerability
Published Dec 9, 2023
·Updated
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by creating a symbolic link.
Affected Software
1 affected component
ncp-e Secure Enterprise Client<12.22
Event History
Dec 9, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-28871?
CVE-2023-28871 is considered to be a moderate severity vulnerability due to its ability to allow unauthorized access to sensitive registry information.
2
How do I fix CVE-2023-28871?
To fix CVE-2023-28871, upgrade NCP Secure Enterprise Client to version 12.22 or later.
3
What systems are affected by CVE-2023-28871?
CVE-2023-28871 affects NCP Secure Enterprise Client versions prior to 12.22.
4
What exploit does CVE-2023-28871 enable?
CVE-2023-28871 enables attackers to create a symbolic link that allows them to read sensitive registry information.
5
Are there any mitigations for CVE-2023-28871?
Currently, the recommended mitigation for CVE-2023-28871 is to ensure you update to the latest version of NCP Secure Enterprise Client.