Local User Access Vulnerability in Npcap by Nmap
CVE-2026-33921
4.8MEDIUM
What is CVE-2026-33921?
The Npcap driver, packaged with the Windows installer, is configured with an insecure default access restriction that allows all local users to utilize the driver. This vulnerability enables non-administrative users to capture network traffic directed to the host. Consequently, sensitive information can be exposed, including data from the host and other devices on the same network segment. Additionally, unauthorized users may send arbitrary raw packets over the network, further compromising network integrity.
Affected Version(s)
Arc Windows 0 < 2.7.0
References
CVSS V4
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was found by Stefano Balzarotti of Nozomi Networks during an internal investigation.
