Client Firewall in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to bypass firewall program execution rules by replacing an allowed program with an arbitrary program.
https://exchange.xforce.ibmcloud.com/vulnerabilities/25242
http://www.securityfocus.com/bid/16906
http://www.securityfocus.com/archive/1/426480/100/0/threaded
http://secunia.com/advisories/19082
http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html