CVE-2024-0980: Path Traversal
Published Mar 27, 2024
·Updated
The Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to execute arbitrary code.
Affected Software
1 affected component
Okta Okta Verify for Windows
Event History
Mar 27, 2024
CVE Published
via MITRE·11:16 PM
Data Sourced
via MITRE·11:16 PM
DescriptionWeakness
Mar 28, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-0980?
CVE-2024-0980 has a high severity rating due to the potential for arbitrary code execution.
2
How do I fix CVE-2024-0980?
To fix CVE-2024-0980, update to the latest version of Okta Verify for Windows as provided by Okta.
3
What are the potential impacts of CVE-2024-0980?
CVE-2024-0980 could allow an attacker to execute arbitrary code, potentially compromising the system.
4
Who is affected by CVE-2024-0980?
Users of Okta Verify for Windows are affected by CVE-2024-0980.
5
Is CVE-2024-0980 being actively exploited?
As of now, there is no public information confirming active exploitation of CVE-2024-0980.