Okta Verify for Windows Auto-update Vulnerability Alert
Date: 2024-03-26
CVE: CVE-2024-0980
Sources: Trust.okta.com Advisory
Issue Summary
Okta Verify's auto-update service for Windows was found vulnerable due to two flaws. These vulnerabilities, when exploited together, could lead to arbitrary code execution on affected systems.
Technical Key Findings
The flaws pertain to improper limitation of a pathname to a restricted directory ("Path Traversal") and uncontrolled search path element ("DLL Hijacking"). Attackers could exploit these vulnerabilities to execute arbitrary code.
Vulnerable Products
- Okta Verify for Windows versions prior to 4.10.7.
- Note: Okta Verify on platforms other than Windows is unaffected.
Impact Assessment
If exploited, attackers could execute arbitrary code in the context of the application, potentially taking control of affected systems.
Patches or Workaround
Upgrade to Okta Verify for Windows version 4.10.7 or later to mitigate this vulnerability.
Tags
#CVE-2024-0980, #OktaVerify, #Windows, #SecurityPatch, #CodeExecution
For the most current information and updates on this issue, please refer to the official Okta security advisories page.