CVE-2024-1470: Elevation of Privilege attack on NetIQ Client login extension
Published Feb 20, 2024
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in NetIQ (OpenText) Client Login Extension on Windows allows Privilege Escalation, Code Injection.This issue
only
affects NetIQ Client Login Extension: 4.6.
Affected Software
2 affected components
NetIQ Client Login Extension
NetIQ Client Login Extension=4.6
Event History
Feb 20, 2024
CVE Published
via MITRE·04:10 PM
Data Sourced
via MITRE·04:10 PM
DescriptionSeverityWeakness
Feb 29, 2024
Data Sourced
via NVD·01:43 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-1470?
CVE-2024-1470 is classified as a high severity vulnerability, allowing for privilege escalation and code injection.
2
How do I fix CVE-2024-1470?
To fix CVE-2024-1470, update the NetIQ Client Login Extension to a version that addresses this vulnerability.
3
What products are affected by CVE-2024-1470?
CVE-2024-1470 affects the NetIQ Client Login Extension version 4.6.
4
What type of vulnerability is CVE-2024-1470?
CVE-2024-1470 is an authorization bypass vulnerability that can be exploited for privilege escalation and code injection.
5
Can CVE-2024-1470 be exploited remotely?
Yes, CVE-2024-1470 can potentially be exploited remotely due to its nature as an authorization bypass vulnerability.