










The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.
Customers using the Okta Verify for Windows client versions 5.1.3 through 6.12.3 are affected.
This applies if the following preconditions are present:
Okta Verify for Windows (versions 5.1.3 through 6.12.3) is installed on the host system.
A local user has low-privileged interactive access to create filesystem junctions on the host.
An administrative user or system process subsequently initiates the uninstallation.
To remediate this vulnerability, upgrade the Okta Verify for Windows client to version 7.0.0 or greater.
Download version 7.0.1 of Okta Verify for Windows
The vulnerability is present in Okta Verify for Windows versions 5.1.3 to 6.12.3 and is resolved in Okta Verify for Windows version 7.0.0.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。