惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
有赞技术团队
有赞技术团队
博客园_首页
H
Help Net Security
GbyAI
GbyAI
aimingoo的专栏
aimingoo的专栏
V
Visual Studio Blog
The Cloudflare Blog
腾讯CDC
Jina AI
Jina AI
Last Week in AI
Last Week in AI
月光博客
月光博客
博客园 - 叶小钗
Google DeepMind News
Google DeepMind News
B
Blog RSS Feed
Blog — PlanetScale
Blog — PlanetScale
人人都是产品经理
人人都是产品经理
Engineering at Meta
Engineering at Meta
Y
Y Combinator Blog
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
爱范儿
爱范儿
N
Netflix TechBlog - Medium
F
Fortinet All Blogs

Okta Trust

Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe Forum21 Europe
Okta Verify for Windows Auto-update Arbitrary Code Execut...
Okta, Inc. · 2024-03-26 · via Okta Trust

Description

The Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to execute arbitrary code.

Affected product and versions

Customers using Okta Verify for Windows prior to version 4.10.7 that have currently installed or previously had installed versions prior to 4.10.7 of Okta Verify for Windows.

Note: Customers using Okta Verify on platforms other than Windows are not affected.

Resolution

The vulnerability is fixed in Okta Verify for Windows version 4.10.7. To remediate this vulnerability, upgrade to 4.10.7 or greater.

CVE details

CVE ID

CVE-2024-0980

Published Date

2024-03-26

Vulnerability Type

Improper Limitation of a Pathname to a Restricted Directory, Uncontrolled Search Path or Element

CWE

CWE–22, CWE-427

CVSS v3

Score:7.1

Vector string:CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Acknowledgements

Okta would like to thank Ryan Wincey of Securifera, Inc. for providing information in addressing this vulnerability.

References

Deploy Okta Verify to Windows devices