2024-08-07 18:03:14 +00:00
{
"id" : "CVE-2024-7061" ,
"sourceIdentifier" : "psirt@okta.com" ,
"published" : "2024-08-07T17:15:52.113" ,
2024-08-28 20:03:15 +00:00
"lastModified" : "2024-08-28T18:25:38.217" ,
"vulnStatus" : "Analyzed" ,
2024-08-07 18:03:14 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate this vulnerability, upgrade to 5.0.2 or greater."
2024-08-11 02:03:12 +00:00
} ,
{
"lang" : "es" ,
"value" : "Okta Verify para Windows es vulnerable a la escalada de privilegios mediante el secuestro de DLL. La vulnerabilidad se solucion\u00f3 en Okta Verify para Windows versi\u00f3n 5.0.2. Para corregir esta vulnerabilidad, actualice a 5.0.2 o superior."
2024-08-07 18:03:14 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2024-08-28 20:03:15 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 7.8 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 5.9
} ,
2024-08-07 18:03:14 +00:00
{
"source" : "psirt@okta.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 5.5 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 3.6
}
]
} ,
"weaknesses" : [
2024-08-28 20:03:15 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-427"
}
]
} ,
2024-08-07 18:03:14 +00:00
{
"source" : "psirt@okta.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-22"
} ,
{
"lang" : "en" ,
"value" : "CWE-427"
}
]
}
] ,
2024-08-28 20:03:15 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:okta:verify:*:*:*:*:*:windows:*:*" ,
"versionEndExcluding" : "5.0.2" ,
"matchCriteriaId" : "951E2564-0B8A-49B9-A130-4647DF323B7E"
}
]
}
]
}
] ,
2024-08-07 18:03:14 +00:00
"references" : [
{
"url" : "https://help.okta.com/oie/en-us/content/topics/releasenotes/oie-ov-release-notes.htm#panel4" ,
2024-08-28 20:03:15 +00:00
"source" : "psirt@okta.com" ,
"tags" : [
"Not Applicable" ,
"Release Notes"
]
2024-08-07 18:03:14 +00:00
} ,
{
"url" : "https://trust.okta.com/security-advisories/okta-verify-for-windows-privilege-escalation-cve-2024-7061/" ,
2024-08-28 20:03:15 +00:00
"source" : "psirt@okta.com" ,
"tags" : [
"Vendor Advisory"
]
2024-08-07 18:03:14 +00:00
}
]
}