Incorrect default permissions in Okta Verify for Windows - CVE-2024-9191

 

Incorrect default permissions in Okta Verify for Windows - CVE-2024-9191

Published: November 2, 2024


Vulnerability identifier: #VU99624
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-9191
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to a missing access restrictions to the OktaDeviceAccessPipe, which enables attackers in a compromised device to retrieve passwords associated with Desktop MFA passwordless logins.

Note, Okta Device Access users not using passwordless login feature are not affected.


Affected software

Okta Verify for Windows

How to mitigate CVE-2024-9191

Install updates from vendor's website.

Okta Verify for Windows - update to 5.3.3

External References

Related Security Bulletins