CVE-2024-7061

Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate this vulnerability, upgrade to 5.0.2 or greater.
Configurations

Configuration 1 (hide)

cpe:2.3:a:okta:verify:*:*:*:*:*:windows:*:*

History

28 Aug 2024, 18:25

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References () https://trust.okta.com/security-advisories/okta-verify-for-windows-privilege-escalation-cve-2024-7061/ - () https://trust.okta.com/security-advisories/okta-verify-for-windows-privilege-escalation-cve-2024-7061/ - Vendor Advisory
References () https://help.okta.com/oie/en-us/content/topics/releasenotes/oie-ov-release-notes.htm#panel4 - () https://help.okta.com/oie/en-us/content/topics/releasenotes/oie-ov-release-notes.htm#panel4 - Not Applicable, Release Notes
CPE cpe:2.3:a:okta:verify:*:*:*:*:*:windows:*:*
First Time Okta
Okta verify
CWE CWE-427

07 Aug 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-07 17:15

Updated : 2024-08-28 18:25


NVD link : CVE-2024-7061

Mitre link : CVE-2024-7061


JSON object : View

Products Affected

okta

  • verify
CWE
CWE-427

Uncontrolled Search Path Element