CVE-2022-23718
EUVD-2022-2865430.06.2022, 20:15
PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker capable of achieving a sophisticated man-in-the-middle position, or to compromise Ping Identity web servers, could deliver malicious code that would be executed as SYSTEM by the PingID Windows Login application.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pingidentity | pingid_integration_for_windows_login | 𝑥 < 2.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration