CVE-2023-28872: Ncp-E Secure Enterprise Client

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\Temp\NcpSupport* location.

Affected products

  • Ncp-E Secure Enterprise Client: before 13.10 (fixed in 13.10)

Published 2023-12-25. Last modified 2026-06-17.