PT-2024-18074 · Netiq · Netiq Client Login Extension

Published

2024-02-20

·

Updated

2025-02-14

·

CVE-2024-1470

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NetIQ Client Login Extension version 4.6
Description The issue allows for Authorization Bypass Through User-Controlled Key, enabling Privilege Escalation and Code Injection in the NetIQ (OpenText) Client Login Extension on Windows.
Recommendations For NetIQ Client Login Extension version 4.6, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-1470

Affected Products

Netiq Client Login Extension