#VU99624 Incorrect default permissions in Okta Verify for Windows - CVE-2024-9191
Published: November 2, 2024
Okta Verify for Windows
Okta
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to a missing access restrictions to the OktaDeviceAccessPipe, which enables attackers in a compromised device to retrieve passwords associated with Desktop MFA passwordless logins.
Note, Okta Device Access users not using passwordless login feature are not affected.