cve/2024/CVE-2024-7061.md
2024-08-08 18:49:29 +00:00

19 lines
967 B
Markdown

### [CVE-2024-7061](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7061)
![](https://img.shields.io/static/v1?label=Product&message=Okta%20Verify%20for%20Windows&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-22%20Improper%20Limitation%20of%20a%20Pathname%20to%20a%20Restricted%20Directory&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-427%20Uncontrolled%20Search%20Path%20or%20Element&color=brighgreen)
### Description
Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate this vulnerability, upgrade to 5.0.2 or greater.
### POC
#### Reference
- https://help.okta.com/oie/en-us/content/topics/releasenotes/oie-ov-release-notes.htm#panel4
#### Github
No PoCs found on GitHub currently.