Okta Device Access Vulnerability: Attackers Can Retrieve Desktop MFA Passwords
CVE-2024-9191
What is CVE-2024-9191?
A vulnerability exists in the Okta Verify agent for Windows that compromises the Device Access features. Specifically, the vulnerability allows attackers who gain access to a user's device to exploit the OktaDeviceAccessPipe, which may enable them to retrieve passwords linked to Desktop MFA passwordless logins. This issue was identified during routine penetration testing and poses risks only to users utilizing the passwordless feature of Okta Device Access. Users of Okta Verify on non-Windows platforms, as well as those exclusively utilizing FastPass, are not affected.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Okta Verify for Windows 5.0.2 < 5.3.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
