NN-2026:14-01

Npcap driver installed without administrator-only access restriction on Windows in Arc before v2.7.0

Last update: 2026-08-11

Advisory IDNN-2026:14-01
TopicNpcap driver installed without administrator-only access restriction on Windows in Arc before v2.7.0
CWE ImpactCWE-1188: Initialization of a Resource with an Insecure Default
Issue date2026-08-11
AffectsArc < v2.7.0
CVE Name(s)CVE-2026-33921
CVSS DetailsCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CVSS Score4.8 (CVSS v4.0)
5.2 (CVSS v3.1)
CVE Risk LevelMedium (CVSS v4.0)
Medium (CVSS v3.1)
Risk Level for Nozomi customersMedium

Summary

The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only.

Impact

A local user without administrative privileges could use the Npcap driver to capture the traffic reaching the host, which discloses information belonging both to the host and to other systems on the same network segment, and to send arbitrary raw packets on that segment.

Affected Products

Arc < v2.7.0

Workarounds and Mitigations

Reinstall Npcap on the affected host with the "Restrict Npcap driver's access to Administrators only" option enabled.

Solutions

Upgrade Arc to v2.7.0 or later.

Modification History

2026-08-11: Initial revision

Related Links

Acknowledgements

We thank the following parties for their efforts:

  • Stefano Balzarotti of Nozomi Networks for finding this issue during an internal investigation

Contact

Nozomi Networks Product Security team can be reached at prodsec@nozominetworks.com.
More contact details on the PSIRT page.