PT-2024-7900 · Okta · Okta Verify
Published
2024-04-17
·
Updated
2024-11-15
·
CVE-2024-9191
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Okta Verify versions 5.0.2 through 5.3.2
Description
The issue is related to the Okta Device Access feature in the Okta Verify agent for Windows, which provides access to the OktaDeviceAccessPipe. This allows attackers on a compromised device to retrieve passwords associated with Desktop MFA passwordless logins. The vulnerability was discovered via routine penetration testing. A precondition for this vulnerability is that the user must be using the Okta Device Access passwordless feature. Users not using passwordless and customers using Okta Verify on platforms other than Windows or only using FastPass are not affected.
Recommendations
For Okta Verify versions 5.0.2 through 5.3.2, upgrade Okta Verify immediately to mitigate risks. As a temporary workaround, consider disabling the Okta Device Access passwordless feature until a patch is available. Restrict access to the OktaDeviceAccessPipe component to minimize the risk of exploitation. Avoid using the Okta Device Access feature for passwordless logins in Desktop MFA until the issue is resolved.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Okta Verify