CVE-2024-0980

HIGH

Okta Verify for Windows < 4.10.7 - Arbitrary Code Execution via Auto-Update Service

Title source: llm
STIX 2.1

Description

The Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to execute arbitrary code.

Scores

CVSS v3 7.1
EPSS 0.0046
EPSS Percentile 36.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22 CWE-427
Status published
Products (1)
Okta/Okta Verify for Windows < 4.10.7
Published Mar 28, 2024
Tracked Since Feb 18, 2026