CVE-2024-7061

Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate this vulnerability, upgrade to 5.0.2 or greater.
Configurations

Configuration 1 (hide)

cpe:2.3:a:okta:verify:*:*:*:*:*:windows:*:*

History

28 Aug 2024, 18:25

Type Values Removed Values Added
Summary
  • (es) Okta Verify para Windows es vulnerable a la escalada de privilegios mediante el secuestro de DLL. La vulnerabilidad se solucionó en Okta Verify para Windows versión 5.0.2. Para corregir esta vulnerabilidad, actualice a 5.0.2 o superior.
First Time Okta verify
Okta
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:okta:verify:*:*:*:*:*:windows:*:*
References () https://help.okta.com/oie/en-us/content/topics/releasenotes/oie-ov-release-notes.htm#panel4 - () https://help.okta.com/oie/en-us/content/topics/releasenotes/oie-ov-release-notes.htm#panel4 - Not Applicable, Release Notes
References () https://trust.okta.com/security-advisories/okta-verify-for-windows-privilege-escalation-cve-2024-7061/ - () https://trust.okta.com/security-advisories/okta-verify-for-windows-privilege-escalation-cve-2024-7061/ - Vendor Advisory

07 Aug 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-07 17:15

Updated : 2024-08-28 18:25


NVD link : CVE-2024-7061

Mitre link : CVE-2024-7061

CVE.ORG link : CVE-2024-7061


JSON object : View

Products Affected

okta

  • verify
CWE
CWE-427

Uncontrolled Search Path Element

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')