Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2024-7061", "assignerOrgId": "59b22baa-87b2-4371-8e4a-e080df12f74a", "state": "PUBLISHED", "assignerShortName": "Okta", "dateReserved": "2024-07-23T21:04:37.452Z", "datePublished": "2024-08-07T16:35:44.403Z", "dateUpdated": "2024-08-09T13:44:51.144Z"}, "containers": {"cna": {"affected": [{"defaultStatus": "unaffected", "product": "Okta Verify for Windows", "vendor": "Okta", "versions": [{"lessThan": "5.0.1", "version": "5.0.1", "status": "affected", "versionType": "semver"}, {"version": "5.0.2", "status": "unaffected", "versionType": "semver"}]}], "datePublic": "2024-08-07T17:00:00.000Z", "descriptions": [{"lang": "en", "value": "Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate this vulnerability, upgrade to 5.0.2 or greater."}], "metrics": [{"cvssV3_1": {"version": "3.1", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "availabilityImpact": "NONE", "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}, "format": "CVSS", "scenarios": [{"lang": "en", "value": "GENERAL"}]}], "problemTypes": [{"descriptions": [{"cweId": "CWE-22", "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory", "lang": "en", "type": "CWE"}, {"cweId": "CWE-427", "description": "CWE-427 Uncontrolled Search Path or Element", "lang": "en", "type": "CWE"}]}], "providerMetadata": {"orgId": "59b22baa-87b2-4371-8e4a-e080df12f74a", "shortName": "Okta", "dateUpdated": "2024-08-07T16:37:01.719Z"}, "references": [{"tags": ["vendor-advisory"], "url": "https://trust.okta.com/security-advisories/okta-verify-for-windows-privilege-escalation-cve-2024-7061/"}, {"url": "https://help.okta.com/oie/en-us/content/topics/releasenotes/oie-ov-release-notes.htm#panel4"}], "solutions": [{"lang": "en", "value": "The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate this vulnerability, upgrade to 5.0.2 or greater."}], "credits": [{"lang": "en", "value": "Okta would like to thank Ryan Wincey of Securifera, Inc. for discovering this vulnerability.", "type": "reporter"}]}, "adp": [{"metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2024-08-09T13:44:41.455152Z", "id": "CVE-2024-7061", "options": [{"Exploitation": "none"}, {"Automatable": "no"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-08-09T13:44:51.144Z"}}]}}