Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gwvc-2mf6-9jv4

Опубликовано: 11 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 4.8
CVSS3: 5.2

Описание

The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privileges could use the Npcap driver to capture the traffic reaching the host, which discloses information belonging both to the host and to other systems on the same network segment, and to send arbitrary raw packets on that segment.

The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privileges could use the Npcap driver to capture the traffic reaching the host, which discloses information belonging both to the host and to other systems on the same network segment, and to send arbitrary raw packets on that segment.

EPSS

Процентиль: 1%
0.001
Низкий

4.8 Medium

CVSS4

5.2 Medium

CVSS3

Дефекты

CWE-1188

Связанные уязвимости

CVSS3: 5.2
redhat
около 1 месяца назад

The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privileges could use the Npcap driver to capture the traffic reaching the host, which discloses information belonging both to the host and to other systems on the same network segment, and to send arbitrary raw packets on that segment.

CVSS3: 5.2
nvd
около 1 месяца назад

The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privileges could use the Npcap driver to capture the traffic reaching the host, which discloses information belonging both to the host and to other systems on the same network segment, and to send arbitrary raw packets on that segment.

EPSS

Процентиль: 1%
0.001
Низкий

4.8 Medium

CVSS4

5.2 Medium

CVSS3

Дефекты

CWE-1188