CVE-2022-23718
30.06.2022, 20:15
PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker capable of achieving a sophisticated man-in-the-middle position, or to compromise Ping Identity web servers, could deliver malicious code that would be executed as SYSTEM by the PingID Windows Login application.Enginsight
Vendor | Product | Version |
---|---|---|
pingidentity | pingid_integration_for_windows_login | 𝑥 < 2.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration