CVE-2022-23718: PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution
PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker capable of achieving a sophisticated man-in-the-middle position, or to compromise Ping Identity web servers, could deliver malicious code that would be executed as SYSTEM by the PingID Windows Login application.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-23718?
CVE-2022-23718 is a vulnerability in PingID Windows Login prior to version 2.8 that can lead to remote code execution.
How severe is CVE-2022-23718?
CVE-2022-23718 has a severity rating of critical with a CVSS score of 8.1.
How does CVE-2022-23718 occur?
CVE-2022-23718 occurs when PingID Windows Login uses known vulnerable components that can be exploited by a man-in-the-middle attack or by compromising Ping Identity web servers.
What is the affected software for CVE-2022-23718?
The affected software for CVE-2022-23718 is PingIdentity Pingid Integration For Windows Login versions prior to 2.8.
How can CVE-2022-23718 be fixed?
To fix CVE-2022-23718, users should update PingID Windows Login to version 2.8 or later.