Security Advisory

CVE-2022-23718

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-06-30 19:25:30
Last updated 2024-08-03 03:51:46
Assigner Ping Identity
State PUBLISHED

Description

PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker capable of achieving a sophisticated man-in-the-middle position, or to compromise Ping Identity web servers, could deliver malicious code that would be executed as SYSTEM by the PingID Windows Login application.