Remote Code Execution Vulnerability in IDExpert Windows Logon Agent by Changing
CVE-2026-2999
9.3CRITICAL
What is CVE-2026-2999?
The IDExpert Windows Logon Agent developed by Changing contains a vulnerability that allows remote attackers to execute arbitrary code on the affected system. By exploiting this flaw, attackers can manipulate the system to download and execute harmful binaries from a remote source without requiring any authentication. This significant security risk highlights the importance of securing systems to prevent unauthorized access and the execution of malicious code.
Affected Version(s)
IDExpert Windows Logon Agent 2.7.3.230719 <= 2.8.4.250925
