CVE-2024-9191: High severity okta verify vulnerability
The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device to retrieve passwords associated with Desktop MFA passwordless logins. The vulnerability was discovered via routine penetration testing.
Note: A precondition of this vulnerability is that the user must be using the Okta Device Access passwordless feature. Okta Device Access users not using passwordless are not affected, and customers only using Okta Verify on platforms other than Windows, or only using FastPass are not affected.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9191?
CVE-2024-9191 is considered to have a high severity due to its potential to expose passwords associated with Desktop MFA passwordless logins.
How do I fix CVE-2024-9191?
To fix CVE-2024-9191, update the Okta Verify agent for Windows to version 5.3.3 or later.
Which versions of Okta Verify for Windows are affected by CVE-2024-9191?
CVE-2024-9191 affects Okta Verify for Windows versions between 5.0.2 and 5.3.3, inclusive.
What impact does CVE-2024-9191 have on user security?
CVE-2024-9191 can allow attackers on a compromised device to retrieve sensitive passwords, undermining user security.
Is CVE-2024-9191 specifically related to Desktop MFA passwordless logins?
Yes, CVE-2024-9191 specifically targets passwords associated with Desktop MFA passwordless logins through the OktaDeviceAccessPipe.