#VU99624 Incorrect default permissions in Okta Verify for Windows - CVE-2024-9191

 

#VU99624 Incorrect default permissions in Okta Verify for Windows - CVE-2024-9191

Published: November 2, 2024


Vulnerability identifier: #VU99624
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-9191
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Okta Verify for Windows
Software vendor:
Okta

Description

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to a missing access restrictions to the OktaDeviceAccessPipe, which enables attackers in a compromised device to retrieve passwords associated with Desktop MFA passwordless logins.

Note, Okta Device Access users not using passwordless login feature are not affected.


Remediation

Install updates from vendor's website.

External links