nProtect Netizen and nProtect Personal contains a flaw that may allow a remote attacker to execute arbitrary code. The problem is that the 'Npos' ActiveX control does not verify the URL of the update site and the origin of the update configuration file. By creating a malicious web site containing a specially crafted update configuration file and tricking a victim to visit that site, it is possible for a remote attacker to download and execute arbitrary files resulting in a loss of integrity.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
OSVDB:
Web Related
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, INCA has released a patch to address this vulnerability.