CVE-2024-7061

Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate this vulnerability, upgrade to 5.0.2 or greater.
Configurations

Configuration 1 (hide)

cpe:2.3:a:okta:verify:*:*:*:*:*:windows:*:*

History

28 Aug 2024, 18:25

Type Values Removed Values Added
CPE cpe:2.3:a:okta:verify:*:*:*:*:*:windows:*:*
First Time Okta verify
Okta
References () https://help.okta.com/oie/en-us/content/topics/releasenotes/oie-ov-release-notes.htm#panel4 - () https://help.okta.com/oie/en-us/content/topics/releasenotes/oie-ov-release-notes.htm#panel4 - Not Applicable, Release Notes
References () https://trust.okta.com/security-advisories/okta-verify-for-windows-privilege-escalation-cve-2024-7061/ - () https://trust.okta.com/security-advisories/okta-verify-for-windows-privilege-escalation-cve-2024-7061/ - Vendor Advisory
Summary
  • (es) Okta Verify para Windows es vulnerable a la escalada de privilegios mediante el secuestro de DLL. La vulnerabilidad se solucionó en Okta Verify para Windows versión 5.0.2. Para corregir esta vulnerabilidad, actualice a 5.0.2 o superior.
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 7.8

07 Aug 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-07 17:15

Updated : 2024-08-28 18:25


NVD link : CVE-2024-7061

Mitre link : CVE-2024-7061

CVE.ORG link : CVE-2024-7061


JSON object : View

Products Affected

okta

  • verify
CWE
CWE-427

Uncontrolled Search Path Element

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')