WGSA-2026-00002

NCP IPSec VPN Client MSI Installer Privilege Escallation (NCPVE-2025-0626)

Medium Published 2026-01-29Updated 2026-07-28

Summary #

During certain actions such as installation, update, or uninstallation, command line windows (cmd.exe) are temporarily opened with the rights of the SYSTEM account. In older versions of Windows, it is possible to execute any commands or programs with SYSTEM privileges in these interactive command prompts. This allows an attacker to bypass administrative protection mechanisms and gain unrestricted access to the system.

CVE identifiers #

No CVE identifiers are associated with this advisory.

Product status #

ProductAffectedNot affected
IPSec VPN Client (NCP)>= 15.0, < 15.33>= 15.33

Solution #

No solution has been published for this advisory.

References #