Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate this vulnerability, upgrade to 5.0.2 or greater.
References
Link | Resource |
---|---|
https://trust.okta.com/security-advisories/okta-verify-for-windows-privilege-escalation-cve-2024-7061/ | Vendor Advisory |
https://help.okta.com/oie/en-us/content/topics/releasenotes/oie-ov-release-notes.htm#panel4 | Not Applicable Release Notes |
Configurations
History
28 Aug 2024, 18:25
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
References | () https://trust.okta.com/security-advisories/okta-verify-for-windows-privilege-escalation-cve-2024-7061/ - Vendor Advisory | |
References | () https://help.okta.com/oie/en-us/content/topics/releasenotes/oie-ov-release-notes.htm#panel4 - Not Applicable, Release Notes | |
CPE | cpe:2.3:a:okta:verify:*:*:*:*:*:windows:*:* | |
First Time |
Okta
Okta verify |
|
CWE | CWE-427 |
07 Aug 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-07 17:15
Updated : 2024-08-28 18:25
NVD link : CVE-2024-7061
Mitre link : CVE-2024-7061
JSON object : View
Products Affected
okta
- verify
CWE
CWE-427
Uncontrolled Search Path Element