CVE-2024-9191: High severity okta verify vulnerability

Published Nov 1, 2024
·
Updated

The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device to retrieve passwords associated with Desktop MFA passwordless logins. The vulnerability was discovered via routine penetration testing.

Note: A precondition of this vulnerability is that the user must be using the Okta Device Access passwordless feature. Okta Device Access users not using passwordless are not affected, and customers only using Okta Verify on platforms other than Windows, or only using FastPass are not affected.

Affected Software

1 affected component
Okta Verify Windows>=5.0.2<5.3.3

Remediation

Information

The vulnerability is present in Okta Verify versions 5.0.2 to 5.3.2 and resolved in Okta Verify for Windows version 5.3.3. To remediate this vulnerability, upgrade Okta Verify for Windows to version 5.3.3 or greater.

Event History

Nov 1, 2024
CVE Published
via MITRE·09:21 PM
Data Sourced
via MITRE·09:21 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-9191?

CVE-2024-9191 is considered to have a high severity due to its potential to expose passwords associated with Desktop MFA passwordless logins.

2

How do I fix CVE-2024-9191?

To fix CVE-2024-9191, update the Okta Verify agent for Windows to version 5.3.3 or later.

3

Which versions of Okta Verify for Windows are affected by CVE-2024-9191?

CVE-2024-9191 affects Okta Verify for Windows versions between 5.0.2 and 5.3.3, inclusive.

4

What impact does CVE-2024-9191 have on user security?

CVE-2024-9191 can allow attackers on a compromised device to retrieve sensitive passwords, undermining user security.

5

Is CVE-2024-9191 specifically related to Desktop MFA passwordless logins?

Yes, CVE-2024-9191 specifically targets passwords associated with Desktop MFA passwordless logins through the OktaDeviceAccessPipe.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203