First published: Thu Jun 30 2022(Updated: )
PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker capable of achieving a sophisticated man-in-the-middle position, or to compromise Ping Identity web servers, could deliver malicious code that would be executed as SYSTEM by the PingID Windows Login application.
Credit: responsible-disclosure@pingidentity.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pingidentity Pingid Integration For Windows Login | <2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23718 is a vulnerability in PingID Windows Login prior to version 2.8 that can lead to remote code execution.
CVE-2022-23718 has a severity rating of critical with a CVSS score of 8.1.
CVE-2022-23718 occurs when PingID Windows Login uses known vulnerable components that can be exploited by a man-in-the-middle attack or by compromising Ping Identity web servers.
The affected software for CVE-2022-23718 is PingIdentity Pingid Integration For Windows Login versions prior to 2.8.
To fix CVE-2022-23718, users should update PingID Windows Login to version 2.8 or later.