Okta Device Access Vulnerability: Attackers Can Retrieve Desktop MFA Passwords
CVE-2024-9191
7.8HIGH
What is CVE-2024-9191?
A vulnerability exists in the Okta Verify agent for Windows that compromises the Device Access features. Specifically, the vulnerability allows attackers who gain access to a user's device to exploit the OktaDeviceAccessPipe, which may enable them to retrieve passwords linked to Desktop MFA passwordless logins. This issue was identified during routine penetration testing and poses risks only to users utilizing the passwordless feature of Okta Device Access. Users of Okta Verify on non-Windows platforms, as well as those exclusively utilizing FastPass, are not affected.
Affected Version(s)
Okta Verify for Windows 5.0.2 < 5.3.3