CVE-2024-7061

O

kta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate this vulnerability, upgrade to 5.0.2 or greater.

Configurations

Configuration 1 (hide)

cpe:2.3:a:okta:verify:*:*:*:*:*:windows:*:*

History

28 Aug 2024, 18:25

Type Values Removed Values Added
CPE cpe:2.3:a:okta:verify:*:*:*:*:*:windows:*:*
First Time Okta verify
Okta
References () https://help.okta.com/oie/en-us/content/topics/releasenotes/oie-ov-release-notes.htm#panel4 - () https://help.okta.com/oie/en-us/content/topics/releasenotes/oie-ov-release-notes.htm#panel4 - Not Applicable, Release Notes
References () https://trust.okta.com/security-advisories/okta-verify-for-windows-privilege-escalation-cve-2024-7061/ - () https://trust.okta.com/security-advisories/okta-verify-for-windows-privilege-escalation-cve-2024-7061/ - Vendor Advisory
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 7.8

07 Aug 2024, 19:09

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-07 17:15

Updated : 2024-08-28 18:25


NVD link : CVE-2024-7061

Mitre link : CVE-2024-7061

CVE.ORG link : CVE-2024-7061


JSON object : View

Products Affected
CWE
CWE-427

Uncontrolled Search Path Element

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')