Impact
The Windows installer for Nozomi Networks Arc deploys the Npcap driver with its access‑restriction option left at the insecure default of allowing all local users to use the driver. A local user who is not an administrator can therefore invoke the driver to capture all traffic that traverses the host and to transmit arbitrary raw packets on the network segment. This exposes both host‑specific information and data from other devices on the same network, compromising confidentiality and enabling a form of local privilege escalation that can be leveraged for further network attacks. The weakness is rooted in missing access control, identified as CWE‑1188.
Affected Systems
Nozomi Networks Arc for Windows versions earlier than 2.7.0 are affected. The vulnerability is present in the Windows installer of Arc and manifests on all hosts running those legacy versions.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity. Exploitation requires local user access; no remote attack vector is identified. Because the EPSS score is unavailable and the vulnerability is not listed in CISA's KEV catalog, the known risk is primarily for environments that have not upgraded Arc or applied the workaround. An attacker with local non‑admin access can exploit the insecure driver to read network traffic and inject malicious packets, potentially facilitating further attacks within the network segment.
OpenCVE Enrichment